Security
DGX Spark/Security hardening a rented GPU instance

Security hardening a rented GPU instance

By Samuel Seidel · Updated September 23, 2026

Renting a Spark gets you a machine with root access and a public network path. What runs on it, and how exposed it is, is entirely your configuration from that point on. This is the in-instance half of security: the steps you take once you are logged in as root. It is deliberately narrow, GPUwerk's own infrastructure-level posture, physical security, network isolation between tenants, and so on, is a separate layer that this page does not speak for, and the site does not publish a specific security certification to cite here.

SSH: the door you actually control

Every instance ships with password authentication disabled, per GPUwerk's SSH key guide, so a key pair is the only way in by default, which already removes the most common brute-force target. From there, the hardening is on you:

Network exposure: expose only what needs exposing

Every instance gets a public HTTPS endpoint routed to port 8888 in the container, and SSH on its own hostname at the standard port 22. Anything else you bind to a port is your call, and the default should be not public.

Don't run services as root just because you land there

SSH puts you in as root, and it's tempting to run everything that way since nothing stops you. Don't. A service running as root that gets compromised, through a dependency vulnerability, a malicious model artifact, or an exposed debug endpoint, gives an attacker root on the box immediately, rather than the more limited blast radius of a service account.

Secrets: don't leave them in shell history or plaintext env files

API keys, model repository tokens, and any credentials for services you call out to need the same discipline you'd use anywhere else.

Ephemeral vs persistent: pick deliberately

A stopped instance keeps its workspace, SSH port, and hostname exactly as they were, billed at 75% of the running rate, per GPUwerk's pricing page. A terminated instance is wiped for the next tenant and your workspace is deleted with no copy kept. That split is also a security decision, not just a billing one:

What this page is not claiming

This is in-instance hardening: what you configure once you have root on a rented machine. GPUwerk's own infrastructure security, isolation between tenants at the platform level, and physical access controls are a separate posture that this page does not describe or vouch for beyond what is already published on GPUwerk's own pages. No specific security certification is claimed here; if that matters for your compliance requirements, ask directly rather than infer one from this guide.

A first engagement can help scope a hardening checklist against your specific compliance requirements before you deploy production traffic.

Start from a clean instance and configure it yourself.

Root access, key-only SSH, and a workspace that stays yours until you terminate it. First top-up: pay $10, get $20 in credit.

Deploy a Spark Read the SSH guide