Open Web UI (Lux GPT) - Secure Internal AI Platform
Agentic Chat and Sandboxed Engineering Terminal (Open WebUI / Lux GPT)
Designed and implemented Open WebUI (Lux GPT) on the KC Enterprise platform—a secure internal AI conversational front end with LDAP authentication (enterprise OIDC cutover path), Postgres-backed persistence, LiteLLM-only chat and RAG routing, Open Terminal (sandboxed engineering terminal in Lux GPT), response watermarking, and custom MCP tools for real-time infrastructure management.
Client
Luxottica
Completion
4 months
Category
Secure AI & Automation
Part of platform
KC Enterprise AI & Operations Platform →Situation
The organization needed a secure, internal conversational AI tool capable of handling sensitive corporate data while providing seamless access to real-time infrastructure information. Existing solutions lacked proper IAM integration, custom tooling capabilities, and the ability to securely query Azure resources without persistent data storage. There was also a need to demonstrate enterprise-grade identity and access management capabilities through LDAP integration.
Task
Design and implement a secure, containerized AI front-end application that provides LDAP-based authentication, integrates with the Light LLM proxy for security guardrails and vector solutions, supports custom MCP tools for real-time infrastructure querying, and enables seamless workflows from data analysis to secure access.
Action
→Shipped Open Terminal (sandboxed engineering terminal in Lux GPT) with multi-user homes, Team Tools preset, and safe post-merge deploy path for engineering workflows
→Migrated Open WebUI from SQLite to Postgres with documented runbook and LiteLLM-only cutover for chat and RAG embeddings
→Configured enterprise response watermark for copied AI content and explicit Traefik routes for chat assets, API, and WebSocket streaming
→Implemented LDAP authentication and user tracking, ensuring all interactions are traceable and accountable
→Integrated with LiteLLM proxy for guardrails, vector stores, and centralized AI governance
→Developed custom AZ Tools MCP integration with device login and 2FA to retrieve secure bearer tokens for Azure queries
→Implemented real-time Azure resource querying across 47 Virtual Machines in two Azure subscriptions
→Created seamless integration with Guacamole MCP tool: analyze infrastructure data, then launch secure access sessions
→Designed ephemeral data handling so bearer tokens and sensitive infrastructure data are erased after MCP sessions
Results
✓Delivered a secure, enterprise-grade internal AI platform with full LDAP authentication and user tracking, demonstrating advanced IAM capabilities
✓Enabled seamless integration between knowledge retrieval, infrastructure analysis, and secure operational access through unified chat interface
✓Established a containerized, portable solution that simplifies deployment and SSL/TLS configuration
✓Provided real-time, factually accurate Azure infrastructure insights without persistent data storage, enhancing security posture
✓Created a scalable architecture ready for AKS deployment with GPU support for high-performance AI workloads
✓Demonstrated proof of concept for secure, internal AI management with custom tooling that can scale across the organization
✓Enabled executive-level reporting with real-time data, improving decision-making speed and accuracy
✓Reduced security risks through ephemeral data handling and comprehensive authentication workflows