live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
analysisAI

Red Hat shows a proxy pattern for adding NeMo Guardrails to LangGraph agents

A first-party walkthrough and example repository put layered input and output checks between an agent and its model without rewriting the LangGraph application.

Guardrails proxy between agent and model with layered safety checks.
AI-generated diagram
By The News Desk· Sep 22, 2026the quick take — two AI hosts go live when you do

Red Hat has published a hands-on walkthrough for adding NeMo Guardrails to a LangGraph agent on Red Hat OpenShift AI without rewriting the graph. The video demonstration, dated September 21, places a guardrails proxy between the agent and an in-cluster vLLM endpoint and shows the guarded and unguarded paths side by side.

What the example changes

The accompanying Guardrailed Agent example uses NeMo Guardrails as a passthrough proxy between a banking customer-service agent and its language model. Red Hat’s repository says that this pattern leaves the agent source unchanged while checking requests and responses against configured rails.

The demonstration layers four checks in sequence: a regex input check, content-safety classification, a topic-boundary check and an output-safety check. In the video’s test, an unguarded agent answers a check-fraud prompt, while the guarded route refuses it; optional tracing then identifies the rail that fired. The repository documents two profiles: a local profile that uses the same model for self-checks, and a nemoguard profile that assigns dedicated classifier roles to the safety layers.

The order matters operationally. According to the example’s architecture notes, a blocking rail stops the chain immediately, allowing a low-cost regex match to reject known patterns before model-backed content and topic checks run. The same repository also documents separate responses for blocked traffic and for an unavailable guardrails service, making failure behavior visible to application teams rather than silently bypassing the filter.

The OpenShift AI integration point

Red Hat’s OpenShift AI 3.5 documentation says NeMo Guardrails is included with OpenShift AI and can be deployed through a NemoGuardrails custom resource managed by the TrustyAI Operator. The service exposes endpoints for guarded chat completions, pass-or-block checks over message histories, and standalone checks that can transform content such as personally identifiable information.

There is an important design boundary in the same documentation: the guarded chat-completions endpoint is not universally transparent and may alter or drop request parameters. Red Hat recommends separating model inference from calls to the guardrail-check endpoint when an application needs transparent payload handling or advanced features such as tool calling.

For platform teams, the useful takeaway is not that one rail configuration fits every agent. It is that the walkthrough provides a reproducible integration seam: keep application orchestration in LangGraph, deploy policy enforcement as an OpenShift-managed service, and test both blocked-content behavior and guardrail outages before promotion. Teams adopting the example should tune topic policy and classifier choices for their own domain rather than treating the banking defaults as production policy.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.