Security guidelines for Lumina deployment
POSTGRES_PASSWORD=<generate-strong-password>
# PostgreSQL ssl = on ssl_cert_file = '/path/to/server.crt' ssl_key_file = '/path/to/server.key'
apiVersion: networking.k8s.io/v1 kind: NetworkPolicy metadata: name: postgres-policy spec: podSelector: matchLabels: app: postgres ingress: - from: - podSelector: matchLabels: app: lumina-api
const redacted = redactPII(userPrompt); await lumina.traceLLM( () => llm.generate(redacted), { prompt: redacted } );
# Kubernetes External Secrets apiVersion: external-secrets.io/v1beta1 kind: ExternalSecret metadata: name: lumina-secrets spec: secretStoreRef: name: aws-secrets-manager data: - secretKey: ANTHROPIC_API_KEY remoteRef: key: prod/lumina/anthropic_key