# Encrypted memory for agents that run somewhere else: what changed in v1.1.0, sgit.ai

> The changes to the article "Encrypted memory for agents that run somewhere else" in v1.1.0, paragraph by paragraph.

*Source: <https://sgit.ai/articles/versions/encrypted-memory-for-isolated-agents/v1.1.0.html> · site v0.7.38 · this file is generated from the same content as the page, so the two cannot drift. Every page on this site has a `.md` twin; internal links below point at them.*

---

[Home](../../../index.md) / [Articles](../../index.md) / [Encrypted memory for agents that run somewhere else](../../encrypted-memory-for-isolated-agents.md) / [Versions](../encrypted-memory-for-isolated-agents.md) / v1.1.0

# Encrypted memory for agents that run somewhere else: what changed in v1.1.0

From v1.0.0 (2026-10-08, `b39da50f2`) to v1.1.0 (2026-10-08, `be27891d9`), paragraph by paragraph.

0 paragraphs added, 0 removed, 5 changed in place, 73 unchanged. About 132 words added and 0 removed. Insertions are marked like this, deletions like this; unchanged runs are folded to one line; figures appear as their file names.

[all versions](../encrypted-memory-for-isolated-agents.md)

50 unchanged paragraphs, under In short, Why isolated agents need memory somewhere else, What is in the box…

!shot dp-cloud.webp | images/ | The server runs on EC2 or Fargate in a private subnet with its objects in S3. Agents inEverything the VPCagentsreachtalkitto is inside the VPC: an internal load balancer on a private address, and behind it the vault server, either the container on EC2, Fargate or Kubernetes, or the same app on Lambda attached to the VPC, with S3 behind both. The Mac mini joins over a VPN, and CloudFront can give the owner a stable name and TLS without a public address on the server.

When the agents run in the cloud, on EC2, as Fargate taskstasks, as Kubernetes pods or on GPU instances, the server can runruns next to them.them, inside the same VPC, because that is where the agents have to reach it. The shape I would use: theancontainerinternalonloadEC2balanceror Fargate inwith a private subnet,address only, the vault server behind it, storage in S3 through a VPC endpoint so the server itself holds nothing it would miss, the agents reachingcallingittheonloada private addressbalancer with the access token, and the Mac mini joining over a site-to-site VPN, so the agents at home and in the cloud share one memory. If you want the vault UI from a phone, CloudFront in front gives the server a stable DNS name and TLS, and can reach antheorigininternalinloada private subnetbalancer through a VPC origin, so the server still has no public address of its own.

ThereBehind the load balancer you pick one of two servers, and both sit inside the VPC. The first is alsothe container, on EC2, as a serverlessFargatevariant:task or as a Kubernetes Deployment. The second is the same FastAPI app on Lambda with the web adapter, behindattachedatoFunctiontheURLVPCorandCloudFront,registered as the load balancer's target, with `s3` storage because Lambda has no disk that lasts. ItLambda scales to zero, which suits memory that is written in bursts.bursts; the container suits agents that clone and push all day. To the agents they look the same: one private address, one access token, the same vault.

Be honest with yourself about the status. The deployment docs mark the CloudFormation templates for Lambda, Fargate and EC2 as written and lint-clean, with live validation in progress, and as written they put a public endpoint in front: a Function URL, a load balancer, an instance with a certificate. The private variantshapeaboveabove, with either server inside the VPC, is how I would adapt them, not a template you can deploy today. The Docker image is the part that is ready.

!source The cloud variant, Mermaid source | images/dp-cloud.webp ``` flowchart LR subgraph aws["Cloud account"] CF["CloudFront<br/>stable DNS name and TLS"] subgraph vpc["VPC: the server has no public route"]route to the vault server"] direction TB SV["sg-send-vault<br/>EC2 instance or Fargate task"] AG["agents: EC2, Fargate tasks,<br/>GPU instances"]instances, Kubernetes pods"] LB["internal load balancer<br/>private address only"] subgraph opts["the vault server: pick one, both inside the VPC"] direction TB SV["sg-send-vault container<br/>EC2, Fargate or Kubernetes"] LM["sg-send-vault on Lambda<br/>web adapter, attached to the VPC<br/>template in progress"] end end S3[("S3 bucket<br/>ciphertext only")] LM["or Lambda with the web adapter<br/>template in progress"] end HOME["Mac mini at home or in the office"] PH["The owner's devices"] AG -- "private address, access"access token" --> LB LB --> SV LB -.-> LM SV -- "SEND__STORAGE_MODE=s3""SEND__STORAGE_MODE=s3<br/>through a VPC endpoint" --> S3 LM -.-> S3 HOME -- "site-to-site VPN into the VPC" --> SVLB PH -- "https, access token" --> CF CF -- "VPC origin" --> SV CF -.-> LMLB```

23 unchanged paragraphs, under Pattern five: two servers, one vault, What a breach of the server gives an attacker, Which pattern, when…

[all versions](../encrypted-memory-for-isolated-agents.md)


---

*[Site index for agents](../../../llms.txt) · [HTML version](https://sgit.ai/articles/versions/encrypted-memory-for-isolated-agents/v1.1.0.html)*
