# Agent-Ready:MCP 网关与 Agent 治理 日期:2026-09-03 ## 场景定义 Agent-Ready 不是“能调 LLM API”,而是企业把 **自主 Agent 当成一种新的工作负载身份** 来治理: - **MCP(Model Context Protocol)网关**:Agent 与工具/数据之间的统一入口,做鉴权、工具过滤、审计、限流。 - **Agent 治理**:身份、使命/意图、最小权限、运行时拦截、HITL、可观测、回收。 - **沙箱**:Agent 生成的代码默认不可信,需要微 VM / 安全容器隔离。 2026-08 末到 09 初,Broadcom、Nutanix、Red Hat 几乎同时把这一层产品化。本卷宗只写 **已在公开网页核验** 的名称,避免把内部传闻当产品。 ## 为何现在重要 - Google Cloud 2026 基础设施报告:83% 组织认为要升级才能跑生产 Agent;79% 把安全/治理/MLOps 列为顶级挑战;Agent 可被授权读邮件、查库、调 API,威胁模型不同于聊天机器人。[Virtualization Review](https://virtualizationreview.com/articles/2026/08/28/agentic-ai-pushes-enterprise-infrastructure-toward-an-upgrade-cycle-google-report-says) - CSA 2026 云威胁榜:IAM 升至第 1;**AI 增强攻击**第 2、**AI 系统被攻陷**第 6,均为新上榜。非人类身份(服务账号、机器人、**AI Agent**)被明确写入 IAM 条目;MCP 与 Agent 权限出现在误配置条目。[Virtualization Review](https://virtualizationreview.com/articles/2026/08/24/identity-ai-lead-csas-2026-cloud-threat-list.aspx) - VMware 介绍 Private AI Cloud 时直接说:OpenAI/Anthropic Agent 逃出沙箱、连到第三方环境的事件,使高安全沙箱成为焦点。[Next Platform](https://www.nextplatform.com/cloud/2026/09/01/vmware-intros-private-ai-cloud-ai-factory-as-workloads-shift-to-on-prem/5293559) - 国内:ZStack 用游戏公司“一夜约 200 万元 Token”的公开演讲当警示(**转述,非审计数字**),Zentrix 把拦截放在调用前。 ## 2025–2026 动态(三项点名核验) ### 1. Broadcom AgentMinder —— 已 GA - 2026-08-31 VMware Explore:AgentMinder 作为企业 Agent 治理与运行时控制,**官方新闻稿写 generally available**。[GlobeNewswire](https://www.globenewswire.com/news-release/2026/08/31/3353342/19933/en/broadcom-unveils-agentminder-an-enterprise-solution-for-ai-agent-governance-and-runtime-control.html) - 能力(**厂商自称**):把 Agent 当企业身份;每次工具调用按使命、意图、上下文、风险授权;云原生 AI 网关只把流量导向授权后端;OpenTelemetry 审计;AuthZEN 对接现有授权栈。 - 与 vDefend、Avi Load Balancer 组成三层:身份/意图、工作负载、威胁检测。[配套稿](https://www.globenewswire.com/news-release/2026/08/31/3353355/19933/en/broadcom-delivers-end-to-end-security-identity-and-observability-for-agentic-ai.html) - SiliconANGLE:AgentMinder 独立于 Agent 运行时;可 allow/deny/redirect/redact;Broadcom **自称**内部用其处理每日约 3600 万客户相关与 700 万员工相关 API 调用——内部用量,不是客户基准。[SiliconANGLE](https://siliconangle.com/2026/08/31/broadcoms-private-ai-cloud-spans-infrastructure-agents-data-and-security/) Tanzu 被指定为 Private AI Cloud 的 Agent 层:deny-by-default 沙箱、MCP、数据产品 marketplace、AI gateway 记日志。 ### 2. Nutanix Agent Gateway —— MCP 管理已 GA - Agent Gateway 在 NAI 2.7 已 GA(统一 Agent→LLM 流量、Token 限流;当时 MCP 为技术预览)。[Nutanix 博客](https://www.nutanix.com/blog/introducing-nutanix-agent-gateway) - 2026-08-26 NAI 2.8:**MCP server 管理在 Agent Gateway 中 GA**。本地或远程 MCP;按用户/API Key 赋工具权限;本地 MCP 滚动升级。[Nutanix 新闻稿](https://www.nutanix.com/press-releases/2026/nutanix-gives-enterprises-the-freedom-to-run-production-agentic-ai-their-way) [产品博客](https://www.nutanix.com/blog/charting-the-path-to-governed-agentic-ai-with-nutanix-enterprise-ai-2-8) - 另一条线:2026-08-10 开源 **NCP MCP server**(Prism v4 API),让 Copilot/Claude Code/Cursor 类工具在 RBAC/限流/审计下操作基础设施。与 Agent Gateway 分工:前者暴露 Nutanix 平台,后者治理 Agent 对任意 MCP 的访问。 - NKP 上可用 Flow 做 Agent 网络隔离(厂商描述)。 ### 3. Red Hat OpenShift 上的 AgentOps / MCP Gateway —— 框架 + 技术预览 核验结果:**“OpenShift AgentOps”不是一个单独 SKU 名称**,而是 Red Hat 把 **AgentOps** 写成 OpenShift AI 上运营 Agent 的框架/控制面。 - Red Hat 主题页定义 AgentOps:监控 Agent 决策、预算、HITL、护栏;并写 Red Hat AI 用 **AgentOps control plane** 覆盖混合云。[Red Hat AgentOps](https://www.redhat.com/en/topics/ai/agentops.md) - 2026 博客:OpenShift/OpenShift AI 是企业 Agent 的基础;AgentOps 是框架无关的运营方法。[Red Hat 博客](https://www.redhat.com/en/blog/agentic-ai-red-hat-openshift-what-enterprises-are-doing-right-now) - **MCP Gateway**:Red Hat Connectivity Link 中的 **技术预览**;在 OpenShift AI 里与 MCP Catalog(开发者预览,AI 3.4 叙述)、身份感知工具过滤、敏感调用审批、MLflow 追踪结合。[Red Hat MCP Gateway TP](https://www.redhat.com/en/blog/control-your-ai-agent-traffic-scale-model-context-protocol-gateway-red-hat-openshift-now-technology-preview) - 开发者蓝图(2026-07-20):MCP Gateway 基于 Envoy + Kuadrant/Authorino;**网关不读 prompt**,用工作负载身份(SPIFFE/Kagenti)决定工具;沙箱列 Kata。[Red Hat Developer](https://developers.redhat.com/articles/2026/07/20/architect-open-blueprint-cloud-native-ai-agents) 规划口径:对标时写 “OpenShift AI AgentOps 框架 + Connectivity Link MCP Gateway(TP)”,不要写成已 GA 的独立产品名。 ### 国内对照 - **ZStack Zentrix**:统一模型接入与 Agent 治理,强调调用前拦截、Token 账。抓取页标题《当 Agent 开始访问核心业务,安全边界怎么守?Zentrix 把拦截放在调用之前》。**厂商内容。** - **SmartX**:船舶制造案例路径是 云底座 → 榫卯 AI 平台(模型网关)→ 智能体平台,反对从开源手工部署直接跳到生产。[抓取](hci-intel/archive/2026-09-03/smartx/企业-ai-和智能体平台为什么需要先建设统一基础设施底座-da18407c.txt) ### 生态层 - Open Secure AI Alliance 2026-09-02 进 Linux 基金会:Agent 运行时、身份、权限、隔离、护栏。SAFE 项目做事件共享。贡献举例:HPE SPIFFE/SPIRE、IBM/Red Hat Lightwell 签名补丁、NVIDIA 自身模型与 harness。[Virtualization Review](https://virtualizationreview.com/articles/2026/09/02/nvidia-founded-open-secure-ai-alliance-moves-to-linux-foundation.aspx) - CrowdStrike Charlotte Agentic SOAR 调备份域(见 `data-domain.md`)——安全 Agent 已在生产工作流里动数据。 ## 谁在卖什么 | 厂商 | 产品名 | 状态(2026-09) | 治理点 | | --- | --- | --- | --- | | Broadcom | AgentMinder + Tanzu Agent 层 | **GA**(2026-08-31) | 身份+意图+每次 tool call | | Nutanix | Agent Gateway + NCP MCP Server | Gateway MCP **GA**;基础设施 MCP 开源 | 工具权限、Token、滚动升级 | | Red Hat | AgentOps 框架 + MCP Gateway | Gateway **技术预览**;Catalog 开发者预览 | Envoy 策略、HITL、追踪 | | ZStack | Zentrix | 已公开宣传 | 调用前拦截、Token 账 | | SmartX | 榫卯 AI + 智能体平台 | 案例阶段 | 先底座再 Agent | | 开源 | MCP、SPIFFE、Kata 沙箱 | 协议层 | 可被上述网关封装 | ## 客户要什么 vs 缺口 **要什么** - 一个入口:所有 Agent 的工具可见性(谁能调 ERP 写操作)。 - 人类审批高风险动作(转账、删资源、改 AD)。 - 审计能回答监管:哪次 prompt、哪个工具、哪个身份、是否被拒。 - Token 与费用按部门/Agent 配额。 - Agent 跑代码有隔离,逃逸不影响 hypervisor。 **缺口** - MCP 服务器爆炸式增长,无网关即影子工具;CSA 已把 MCP 列入误配置面。 - AgentMinder / Nutanix / OpenShift 三套模型不同(意图 vs 工具 ACL vs 工作负载身份),客户会要求“能否对接现有 IAM”,而不是再买一套身份。 - 沙箱密度:每个 Agent 会话一个微 VM 会打爆边缘与 CPU 集群(见 `runtime.md`)。 - 国内等保/密评还没有把 MCP 网关写成控制项,但金融客户已在询。 ## 对我方产品规划的可执行含义 1. **MCP Gateway 作为 2026 必做平台组件**,哪怕第一期只做:统一 endpoint、API Key、只读/读写工具分级、全量审计。对标 Nutanix 2.8 的 GA 范围,而不是等 AgentMinder 级意图引擎。 2. **Agent 身份接入现有 RBAC/AD/OAuth**,用 SPIFFE 或证书,不要只发一个长寿命 Key。CSA 第 1 名就是这件事。 3. **默认 deny 的代码执行沙箱**(Kata 或 Firecracker),与模型网关分开部署。VMware 已把沙箱写成 Private AI Cloud 卖点。 4. **基础设施 MCP 要有独立产品边界**:只读先 GA(查集群、查告警),写操作必须走审批。Nutanix 开源 NCP MCP 会让客户拿 Copilot 直接改生产——我方若做,默认只读。 5. **与备份/安全联动预留 API**(锁定、隔离、回收),否则 SOAR 会绕过虚拟化平台。 6. **话术:Agent-Ready = 网关 + 身份 + 沙箱 + 观测,四件套。** 缺一不可写成“智能体平台”。 ## 出处 - AgentMinder 新闻稿:https://www.globenewswire.com/news-release/2026/08/31/3353342/19933/en/broadcom-unveils-agentminder-an-enterprise-solution-for-ai-agent-governance-and-runtime-control.html - Broadcom 安全三件套:https://www.globenewswire.com/news-release/2026/08/31/3353355/19933/en/broadcom-delivers-end-to-end-security-identity-and-observability-for-agentic-ai.html - SiliconANGLE:https://siliconangle.com/2026/08/31/broadcoms-private-ai-cloud-spans-infrastructure-agents-data-and-security/ - Nutanix Agent Gateway 介绍:https://www.nutanix.com/blog/introducing-nutanix-agent-gateway - NAI 2.8:https://www.nutanix.com/blog/charting-the-path-to-governed-agentic-ai-with-nutanix-enterprise-ai-2-8 - Red Hat AgentOps:https://www.redhat.com/en/topics/ai/agentops.md - OpenShift MCP Gateway TP:https://www.redhat.com/en/blog/control-your-ai-agent-traffic-scale-model-context-protocol-gateway-red-hat-openshift-now-technology-preview - CSA 2026 威胁:https://virtualizationreview.com/articles/2026/08/24/identity-ai-lead-csas-2026-cloud-threat-list.aspx - Google Agent 基础设施:https://virtualizationreview.com/articles/2026/08/28/agentic-ai-pushes-enterprise-infrastructure-toward-an-upgrade-cycle-google-report-says