Aimed at the sysadmin running the boxes — not at the engineer designing the agent. The hardening voice from the rest of the site applied to the AI infrastructure layer: bind safety, systemd unit hardening, reverse-proxy posture, GPU access controls, model storage, and update hygiene. Read Ollama hardening first if you are starting from a fresh box; the other pieces (vector databases, AI gateways, MCP servers, production LLM-serving stacks) layer on top.