live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
guideAI

NeMo Guardrails gives LangGraph agents a separate safety proxy on OpenShift AI

Red Hat’s example keeps LangGraph in charge of reasoning and tools while moving input, output and topic policy into a TrustyAI-managed service.

LangGraph agent behind a separate guardrails proxy on OpenShift AI.
AI-generated diagram
By The News Desk· Oct 5, 2026the quick take — two AI hosts go live when you do

Red Hat has published a deployable pattern for putting NVIDIA NeMo Guardrails between a LangGraph agent and its model endpoint on OpenShift AI. The design changes the agent’s BASE_URL to the guardrails service rather than embedding safety logic in the agent, letting LangGraph retain its conversation loop, system prompt and tool calls while the proxy inspects traffic in both directions. The accompanying banking example is available in Red Hat’s agentic starter kits repository. Red Hat Developer Example repository

Policy becomes a separately operated service

On OpenShift AI, the TrustyAI Operator provisions the service from a NemoGuardrails custom resource and ConfigMap. The example points its main role at an in-cluster vLLM endpoint and can assign dedicated NVIDIA NIM classifiers to content-safety and topic-control roles. Red Hat’s platform documentation confirms that NeMo Guardrails is deployed through the TrustyAI-managed CRD and supports input and output controls, standalone checks and transformations such as sensitive-data redaction. Red Hat Developer OpenShift AI documentation

The supplied configuration runs inexpensive regex checks first, then content-safety and banking-topic classifiers, and finally an output content-safety check. A failed rail short-circuits later checks and returns a configured refusal. Operators can replace the banking policy, add patterns or point each classifier role at a different model without rewriting the agent’s business logic. Example repository

Two traces expose different failure domains

The pattern also separates observability. MLflow records the LangGraph conversation, tool calls and the proxy as an ordinary model endpoint; OpenTelemetry exposes the individual rail spans, including which check blocked and how long each layer took. That split gives platform teams a way to distinguish agent behavior from policy behavior when tuning false positives or investigating refusals. Red Hat Developer

There is an operational caveat. OpenShift AI’s documentation warns that the /v1/chat/completions guardrails endpoint is not universally transparent and may modify or drop request parameters or response fields depending on configuration. The repository’s passthrough: true profile is designed for agent tool traffic, but teams should test their actual streaming, tool-call and error contracts before treating the proxy as a drop-in endpoint. Red Hat documents the standalone /v1/guardrail/checks path as an alternative when inference and policy enforcement need to remain discrete. OpenShift AI documentation

The practical change is architectural rather than cosmetic: safety policy becomes a versioned, observable OpenShift workload with its own models, configuration and failure behavior. That makes guardrail ownership separable from application-agent development—but also gives the platform team another service contract to operate and verify. Red Hat Developer

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.