A public safety agency secures AI data delivery with F5
A secure, highly available data path carries robot and drone sensor data into storage and on to RAG pipelines for a national public safety technology agency.
Autonomous platforms generate continuous vision and sensor data that a national public safety technology agency stores, transforms, and feeds into RAG services. F5 BIG-IP r4600 appliances sit in front of the agency’s Weka and VAST Data storage to secure and load balance that ingestion path, protecting data at the perimeter and ensuring reliably up-to-date data for AI applications.
Business Challenge
A national science and technology agency develops advanced systems that help frontline officers keep the public safe. Among its most forward-leaning programs is a proof of concept for autonomous robotics platforms, including ground robots and drones deployed to support field operations. These platforms carry computer vision systems, object detection mechanisms, and sensor fusion technologies that generate continuous streams of imagery, telemetry, and event data from the moment they leave the depot.
All that data lands in the agency’s private cloud, where it is written through S3-compatible interfaces into high-performance storage built on WEKA and VAST Data solutions. From there, datasets are retrieved, transformed as required, and ingested into retrieval-augmented generation (RAG) services that support the agency’s AI-driven applications. The freshness and integrity of the data moving through that pipeline directly shape how well the AI performs, which is critical in an environment where the AI supports real-time operational decision making. A delayed or compromised data path is not an inconvenience. It is an operational risk.
The agency’s primary challenge was to implement a robust perimeter security framework to protect these data sources before they reach the WEKA and VAST Data storage environments. Device-generated data arrives from the field, crosses the network perimeter, and lands on storage APIs that were never designed to defend themselves. The agency needed to inspect and control that traffic at the edge, authenticate every source allowed through, and do it without slowing ingestion or disrupting the applications enabled by the data.
The storage layer also has to keep pace as the program grows. Every new robot, drone, and sensor package adds to the stream, and every new AI use case adds readers on the other side. The agency needed a front door for its storage that could secure that flow and scale with it.
Solutions
The agency deployed F5 rSeries hardware in an r4600 “Best Bundle” configuration to build a secure, highly available data path in front of its WEKA and VAST Data storage clusters. The architecture, validated during the proof of concept, places F5 BIG-IP Local Traffic Manager (LTM) and F5 BIG-IP Advanced WAF in the DMZ to deliver web application firewall (WAF), API gateway, S3, and DNS services at the perimeter. From there, BIG-IP LTM load balances traffic into the private cloud platform, where virtual machines, Kubernetes-based services, and the storage environment run.
On the data plane, BIG-IP LTM intelligently distributes S3 object requests across storage nodes to keep throughput high and the service available. It continuously monitors node health and steers ingestion traffic away from stressed nodes before a hot spot can stall the pipeline, and it does so consistently across both the WEKA and VAST Data environments, giving the agency one data path into heterogeneous storage. BIG-IP LTM also abstracts the storage endpoint behind a single stable address, an equally important component for the storage operations team. Nodes can be added, retired, or rebalanced behind that address while robots in the field and RAG services in the data center stay connected. That enables storage administrators to spin up clusters in the midst of operations rather than waiting for a maintenance window.
Meanwhile, the F5 WAF and API security services are positioned in the data path directly before storage, inspecting S3 API calls before they ever reach the cluster. Access control, implemented in the first phase of the multi-phase deployment, ensures that only authenticated and authorized sources can write to or read from the environment. The agency’s deployment roadmap extends the same enforcement point to AI runtime security, with the F5 services inspecting inference traffic as the agency’s RAG applications move from proof of concept toward production.
The result is a single control point for security and traffic in the data path prior to the storage environment. Data is protected on the way in and kept flowing on the way out.
Results
Reliable data ingestion for robotics AI
Ground robots and drones now stream vision, detection, and sensor fusion data through a secure and highly available path into storage. If a storage node degrades, BIG-IP LTM routes around it so data ingestion continues. The AI applications those platforms depend on can reliably access the data they need for real-time operational decision making.
One secure front door for storage APIs
WAF, API security, and access control services now sit at a single enforcement point in front of the S3 environment. Every request is inspected and authenticated before it touches a storage node, so the safety of the data doesn’t depend on every client behaving well. With a hardened perimeter in place, the storage team is no longer the last line of defense.
Keep RAG pipelines fed and fresh
With a dependable ingestion path, datasets are retrieved from object storage, transformed, and ingested into RAG services without interruption. Fresh, complete data makes the agency’s AI-driven applications more accurate, resilient, and trustworthy for the officers who rely on them.
Scale storage without touching the apps
Endpoint changes and hot spots can be very disruptive to a high-performance platform like WEKA or VAST Data storage without an application delivery tier in front of the cluster. Because BIG-IP LTM abstracts the storage endpoint, however, the agency can expand its WEKA and VAST Data clusters without redirecting a single application or field platform. Storage administrators add nodes and rebalance data behind a stable address, with health monitoring and traffic steering protecting the cluster as it grows.
A blueprint for AI data delivery
The results the agency achieved for its WEKA and VAST Data storage apply to any organization feeding AI from a storage cluster, whether a commodity S3-compatible object store or a high-performance data platform built for training and inference. As RAG data ingestion grows, a dedicated delivery and security tier turns storage that may be straining to keep up into a pipeline that is protected and ready to scale. As the agency’s robotics program grows, its data path is ready.
Benefits
- Secure ingestion from field devices to storage
- Protect storage APIs with WAF and access control
- Keep RAG pipelines fed with fresh data
- Scale storage behind one stable endpoint
Challenges
- Surging robot, drone, and sensor telemetry
- An exposed data path into object storage
- Real-time decisions demanding reliable data