<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Olivares AI — 博客</title><description>关于在真实基础设施上安全运行 AI 智能体的技术文章：访问关系图、最小权限漂移、审计 Claude Code 与 MCP，以及自托管 AI 治理。</description><link>https://olivares.ai</link><language>zh</language><item><title>审计证据，验证者可以离线检查</title><link>https://olivares.ai/zh/blog/audit-evidence-offline-verification</link><guid isPermaLink="true">https://olivares.ai/zh/blog/audit-evidence-offline-verification</guid><description>拥有每个事件签名和导出的哈希链账本如何生成审计证据，使外部验证者可以独立确认，而无需信任创建它的系统。</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>audit</category><category>ledger</category><category>OSCAL</category><category>Ed25519</category><category>compliance</category></item><item><title>针对 Claude Code 的工作负载身份联合的短期凭证</title><link>https://olivares.ai/zh/blog/ephemeral-credentials-claude-code-workload-identity</link><guid isPermaLink="true">https://olivares.ai/zh/blog/ephemeral-credentials-claude-code-workload-identity</guid><description>静态 API 密钥永不过期，共享身份，并静默地影子联合。WIF 用经验证的 JWT 交换短期每会话令牌来替代它们。</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>WIF</category><category>ephemeral-credentials</category><category>Claude Code</category><category>workload-identity</category></item><item><title>在钩子内部的 PEP：在 Claude Code 内部实施拒绝关闭策略</title><link>https://olivares.ai/zh/blog/hooks-pep-deny-closed-policy-claude-code</link><guid isPermaLink="true">https://olivares.ai/zh/blog/hooks-pep-deny-closed-policy-claude-code</guid><description>PEP 如何将每个 Claude Code 钩子事件分类为门控、上下文或观察，为每个事件连接正确的输出模式，并拒绝关闭未知事件。</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>Claude Code</category><category>hooks</category><category>policy-as-code</category><category>deny-closed</category></item><item><title>使用 RFC 9728 和 RFC 8707 管理 MCP 服务器——实际有效的方法</title><link>https://olivares.ai/zh/blog/governing-mcp-servers-rfc-9728-8707</link><guid isPermaLink="true">https://olivares.ai/zh/blog/governing-mcp-servers-rfc-9728-8707</guid><description>MCP 规范强制要求受保护服务器使用 OAuth 2.1 流程。本文跟踪 401 响应后的流程、RFC 实际提供的内容，以及安全隐患所在。</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>MCP</category><category>RFC 9728</category><category>OAuth</category><category>security</category></item><item><title>许可与观察：漂移作为一等发现</title><link>https://olivares.ai/zh/blog/permitted-vs-observed-drift-finding</link><guid isPermaLink="true">https://olivares.ai/zh/blog/permitted-vs-observed-drift-finding</guid><description>AI代理被允许做的事情与实际观察到的行为之间的漂移会成为一个结构化、分类的发现，并附有置信水平——而不仅仅是一条日志记录。</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>least-privilege</category><category>drift</category><category>access-map</category><category>observability</category></item><item><title>自托管治理在Claude应用网关旁边：联合部署指南</title><link>https://olivares.ai/zh/blog/self-hosted-claude-apps-gateway-co-deployment</link><guid isPermaLink="true">https://olivares.ai/zh/blog/self-hosted-claude-apps-gateway-co-deployment</guid><description>Anthropic的应用网关处理Claude的OIDC认证。你的系统不仅仅是Claude。这是管理两条路径的联合部署架构。</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>self-hosted</category><category>Claude</category><category>co-deployment</category><category>architecture</category></item><item><title>您的 AI 智能体究竟能触达什么：在真实基础设施上绘制智能体访问地图</title><link>https://olivares.ai/zh/blog/map-what-your-ai-agents-can-reach</link><guid isPermaLink="true">https://olivares.ai/zh/blog/map-what-your-ai-agents-can-reach</guid><description>一个 AI 智能体持有凭证、被允许执行某些操作，又被观测到正在执行另一些操作。访问地图揭示了二者之间的差距——以及最小权限在哪里悄然失守。</description><pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate><category>agent-access</category><category>least-privilege</category><category>observability</category><category>audit</category></item><item><title>在自托管环境中审计 Claude Code 与 MCP 服务器</title><link>https://olivares.ai/zh/blog/auditing-claude-code-and-mcp-self-hosted</link><guid isPermaLink="true">https://olivares.ai/zh/blog/auditing-claude-code-and-mcp-self-hosted</guid><description>如何在不离开自有边界的前提下，为 Claude Code 和 MCP 服务器构建审计级追踪链：按代理划分的身份、哈希链账本，以及不可信的 MCP 信号。</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><category>MCP</category><category>Claude Code</category><category>audit</category><category>self-hosted</category></item><item><title>最小权限漂移：在事故发生前发现权限过高的 AI 代理</title><link>https://olivares.ai/zh/blog/least-privilege-drift-for-ai-agents</link><guid isPermaLink="true">https://olivares.ai/zh/blog/least-privilege-drift-for-ai-agents</guid><description>AI 代理获取访问权限的速度远超任何人的审查速度。学习如何通过“授予 vs 观测”差异比对，并在访问时强制执行策略，从而检测最小权限漂移。</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>least-privilege</category><category>ai-agents</category><category>policy-as-code</category><category>audit</category></item><item><title>自托管 AI 治理与数据驻留：最有力的 GDPR 论证</title><link>https://olivares.ai/zh/blog/self-hosted-ai-governance-data-residency-gdpr</link><guid isPermaLink="true">https://olivares.ai/zh/blog/self-hosted-ai-governance-data-residency-gdpr</guid><description>为什么自托管 AI 平台是 GDPR 下最有力的数据驻留态势：治理工具永远不会接触到您的数据。只记录边，而非负载。</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>data-residency</category><category>gdpr</category><category>self-hosted</category><category>ai-governance</category></item><item><title>被动发现 vs 代理：在不介入数据路径的前提下清点 AI 智能体</title><link>https://olivares.ai/zh/blog/passive-discovery-vs-proxies-ai-agents</link><guid isPermaLink="true">https://olivares.ai/zh/blog/passive-discovery-vs-proxies-ai-agents</guid><description>查看 AI 智能体的两种方式：一种是高影响半径的内联代理，另一种是基于日志、OpenTelemetry 和 eBPF 兜底的被动发现。一次诚实的权衡。</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>passive-discovery</category><category>observability</category><category>eBPF</category><category>least-privilege</category></item></channel></rss>