Infrastructure · Data store

Encrypted Model Volume

Data storeInfrastructureInfrastructurearc:EncryptedModelVolume

An encrypted persistent storage volume local to a serving node that caches model weights, and at edge sites application data and logs, unreadable without externally held keys.

Responsibility. Persists model artifacts near the accelerator while protecting them at rest.

Also known as: Persistent volume for model caching, Encrypted edge volume

is read byis read byis written byhas access controlled byLLM Inference Service: is read byLLM Inference ServiceInference Server: is read byInference ServerEdge Device Agent: is written byEdge Device AgentKey Management Service: has access controlled byKey Management Service
Direct neighbourhood (hover for relationship types)

Relationships

is read by dependency

is written by dependency

has access controlled by control

Design guidance

Classification

Quality attributes
Privacy (NIST AI RMF: privacy-enhanced)Reliability (ISO/IEC 25010 | NIST AI RMF: valid and reliable)
Risks mitigated
Model weight theft from stolen hardware or storageSlow restarts from repeated model downloads

Sources

  1. Ch4.5: T. Nguyen, "NVIDIA NIM and Triton Inference Server," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 4.5. ISBN: 9798244538229.
  2. Ch4.6: T. Nguyen, "TensorRT-LLM and NVIDIA Fleet Command," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 4.6. ISBN: 9798244538229.