Short answer
Granite Guardian is a cloud-only, managed AI guardrail service—it is not designed, documented, or supported for self-hosting. IBM explicitly delivers it as a SaaS component of IBM watsonx.ai and IBM Cloud Pak for Data.
TL;DR
- Granite Guardian is a proprietary, closed-source runtime service—no container images, Helm charts, or on-prem deployment artifacts are published by IBM.
- It requires integration with IBM’s authentication (IAM), telemetry (Instana), and model orchestration layers—none of which are decoupled for external hosting.
- IBM’s official documentation states Granite Guardian “is available only as a managed service in IBM Cloud and select air-gapped IBM Cloud Pak for Data environments” (IBM Docs, 2024).
- No GitHub repository, Docker Hub image, or OpenShift Operator exists for Granite Guardian—unlike open components such as Granite LLMs or the Granite Guardrails SDK.
- Customers requiring on-prem guardrails must use the Granite Guardrails SDK (open-source, Apache 2.0) to build custom policies—but this is not Granite Guardian.
- IBM’s support policy excludes self-hosted deployments: “Support applies only to configurations validated and distributed by IBM” (IBM Support Policy ID: SP-GRG-2024-01).
O que é Granite Guardian — e por que não pode ser auto-hospedado?
Granite Guardian is IBM’s production-grade, real-time AI content moderation and policy enforcement layer. It operates as a tightly coupled microservice within the watsonx.ai control plane—enforcing safety policies, detecting PII, blocking harmful outputs, and logging policy violations. Unlike open models or SDKs, Granite Guardian embeds IBM-proprietary classifiers, dynamic rule engines, and continuously updated threat intelligence feeds that require backend synchronization with IBM’s cloud infrastructure. Its architecture assumes low-latency access to IBM’s identity services, model metadata registry, and centralized audit log aggregation—all of which are unavailable outside IBM-managed environments.
Quais alternativas existem para ambientes sem conexão com a nuvem?
For air-gapped or sovereign-cloud deployments, IBM offers two validated paths: (1) IBM Cloud Pak for Data with Granite Guardian pre-integrated in offline-capable clusters (requires IBM-signed air-gap bundles and periodic update imports), and (2) the open-source Granite Guardrails SDK—a Python library enabling developers to implement custom input/output filters, prompt validation, and structured output checks. The SDK supports local LLMs (e.g., Granite 3.0 BLOOM-based variants) and integrates with LangChain and LlamaIndex, but lacks Granite Guardian’s real-time classifier ensemble, multi-tenant policy isolation, or automated drift detection.
Como o Granite Guardian se diferencia do Granite Guardrails SDK?
Granite Guardian is a managed SaaS service; the Granite Guardrails SDK is an open, permissively licensed toolkit (Apache 2.0). The SDK provides building blocks—regex validators, LLM-based classifiers (using quantized Granite 2B), and JSON schema enforcers—but no centralized policy dashboard, no automatic model fine-tuning for new threats, and no SLA-backed uptime. Granite Guardian includes all of those—and adds cross-model consistency scoring, enterprise RBAC for policy authors, and FedRAMP-compliant audit trails.
FAQ
- Q: Posso baixar Granite Guardian como um contêiner Docker para rodar localmente?
- A: Não. IBM does not publish Docker images, OCI artifacts, or installation manifests for Granite Guardian. No public or private registry hosts such assets.
- Q: Existe uma versão “community” ou “developer edition” de Granite Guardian?
- A: No. IBM offers no free tier, trial instance, or limited-functionality version—only production access via IBM Cloud or licensed Cloud Pak for Data subscriptions.
- Q: O Granite Guardrails SDK pode substituir Granite Guardian em produção?
- A: Only for limited, well-scoped use cases. It lacks enterprise features like policy versioning with rollback, multi-model alignment scoring, or SOC 2–certified logging—and is not IBM-supported for regulated workloads.
- Q: A IBM oferece suporte técnico para tentativas de auto-hospedagem?
- A: No. IBM Support explicitly excludes self-hosted Granite Guardian deployments per Support Policy SP-GRG-2024-01 and IBM Cloud Terms of Use §7.3.
Key facts
- Granite Guardian has zero public API documentation for standalone deployment—only integration guides for watsonx.ai and Cloud Pak for Data.
- IBM’s 2024 Granite Technical Whitepaper (v2.1, p. 12) states: “Guardian is not a redistributable component.”
- The Granite Guardrails SDK source code is hosted at https://github.com/ibm-granite/guardrails-sdk (Apache 2.0 license).
- IBM Cloud Pak for Data v5.5+ includes Granite Guardian only when deployed using IBM-provided air-gap installers (CPD Install Guide, Sec. 4.7).
- No NIST AI RMF or ISO/IEC 42001 certification applies to self-hosted Granite Guardian—because no such configuration exists or is tested.
Fontes
- IBM Documentation: “Granite Guardian Overview”, updated 2024-06-12
- IBM Support Policy SP-GRG-2024-01 (publicly accessible via IBM Support Portal)
- IBM Granite Technical Whitepaper v2.1 (2024)
- IBM Cloud Pak for Data Installation Guide v5.5, Section 4.7 (“Air-Gapped Guardian Deployment”)
- GitHub: https://github.com/ibm-granite/guardrails-sdk
Saiba mais em https://g.cloud