Skip to main content

I'm always excited to take on new projects and collaborate with innovative minds.

Location

Cincinnati, Ohio, United States

Social

← Back to Projects
Secure AI & Automation

KC Enterprise AI & Operations Platform

Internal agentic platform for governed chat, sandboxed execution, and review-controlled knowledge in production

Architected Luxottica NA's internal agentic work platform: Lux GPT for governed chat and RAG, Open Terminal (sandboxed engineering terminal in Lux GPT) for safe execution, and KC-Wiki for agent-accessible knowledge with LDAP-backed publishing workflows—all routed through LiteLLM, Traefik, and enterprise observability on a GitLab-managed Podman stack.

Client

Luxottica

Completion

Ongoing

Category

Secure AI & Automation

Situation

Retail IT needed a unified internal platform for secure AI adoption, Azure operational visibility, privileged access, and agentic knowledge management—not a collection of disconnected pilots. Stakeholders required audit-friendly guardrails, cost controls, and integration across chat, inventory MCP, wiki, and jump-server workflows.

Task

Design, integrate, and operate a production agentic platform where Lux GPT, Open Terminal, Azure inventory MCP, KC-Wiki automation, and security services share one LiteLLM control plane with observability and documented runbooks for store and corporate IT partners.

Action

  • Shipped Open Terminal inside Lux GPT: multi-user sandboxed engineering environments with Team Tools presets for safe operational workflows

  • Established LiteLLM as the shared AI control plane—model routing, guardrails, Skill Hub, enterprise OIDC SSO—for chat, wiki automation, and MCP tools

  • Built KC-Wiki as an agentic knowledge layer: LDAP-authenticated MediaWiki, automated document ingest with LiteLLM guardrails, and human review before publish

  • Exposed wiki content to agents via MediaWiki MCP so Lux GPT can ground answers and write back governed updates—not just retrieve static docs

  • Integrated MCP tooling for live operations: ephemeral-token Azure inventory and programmatic privileged access

  • Unified production services on Traefik-routed Podman with Grafana KPI dashboards, self-hosted Sentry-compatible error tracking, GitLab CI, and documented runbooks

  • Partnered with retail IT, audit, and security stakeholders to consolidate disconnected pilots into one internal platform

Results

  • Closed the agentic loop: operators chat, query live infrastructure, execute in Open Terminal, and publish durable knowledge to KC-Wiki with review controls

  • Delivered an integrated enterprise AI and ops platform replacing fragmented AI/inventory/wiki pilots with one production stack

  • Enabled stakeholder-facing secure AI with guardrails, cost tracking, Skill Hub adoption, and live Azure MCP context without persistent sensitive storage

  • Improved audit and operational readiness through provisioned Grafana dashboards, runbooks, and GitLab-managed IaC

Technologies Used

LiteLLMOpen WebUIModel Context Protocol (MCP)TraefikPodmanMediaWikin8NPythonTypeScriptPrometheusGrafanaKeycloakPostgreSQLApache GuacamoleMicrosoft AzureGitLab CI

Security Skills Applied

AI Security & AlignmentPrivileged Access Management (PAM)Audit LoggingLDAPEphemeral Data HandlingContainer SecurityObservability

Let's connect

LinkedIn
Ilya Sulakov
Location
Cincinnati, Ohio, United States