Inspiration
Every VFX supervisor has a horror story.
A junior artist leaves an uncompressed volumetric smoke pass in the render queue on a Friday evening. No one is watching. By Monday morning, a single shot sequence has burned $40,000 on cloud GPUs.
The industry's current solution to this problem is a Slack message: "hey farm team, don't let shot 14 run over budget."
That message is the policy. It lives in Slack. It is unverifiable, unmeasurable, and forgotten by Monday morning.
We built StudioGate because GPU budget policy deserves to be a cryptographic law — not a wish.
What it does
StudioGate is an autonomous VFX governance engine that sits directly between AI render agents and GPU compute clusters.
When an autonomous workflow submits a render job, StudioGate intercepts it before a single GPU cycle is consumed:
The Deterministic Policy Engine evaluates live rolling spend from ClickHouse Cloud using pure Python arithmetic — no LLM, no hallucination risk. If the job breaches the episodic budget ceiling, it is blocked cold in under 2ms.
Gemini 3.6 Flash then acts as an Autonomous VFX Supervisor via the Google ADK tool-calling loop. It receives the blocked frame as a direct image input, performs spatial frequency and volumetric optical density analysis, and uses ADK function calling to synthesize and output the strict JSON remediation payload — specifying target resolution, spot instance cluster routing, cost projection, and verified delivery window — which StudioGate executes directly without human rewriting.
Every decision — approved or blocked — is committed to an immutable SHA-256 cryptographic hash-chain stored in ClickHouse Cloud. The chain is strictly falsifiable: mutate one character and the verifier breaks. Gemini cannot rewrite this history. No one can.
How we built it
Private Layer (Decides):
policy_engine.py — pure Python standard library arithmetic
enforcing hard budget ceilings. 37 unit tests passing. Zero
LLM calls in the verdict loop.
Public Layer (Executes): Gemini 3.6 Flash via Google ADK receives the blocked frame as a PIL image alongside shot metadata and synthesizes a studio-grade remediation: resolution downgrade, spot instance routing, and delivery window verification.
ClickHouse Cloud (Ground Truth): Two simultaneous use cases with deliberate engine selection:
- Real-time rolling burn aggregation using an
AggregatingMergeTree engine —
SUM(gpu_cost_per_sec * duration_sec)over 50,000 telemetry rows ordered by(job_type, timestamp). Median query latency: 207ms. - Append-only cryptographic audit ledger using a standard MergeTree engine — every governance decision stored with SHA-256 hash-chaining in insertion order. Median chain verification latency: 184ms.
hashledger: We extracted the core hash-chain engine into a standalone, zero-dependency open-source Python package so any production audit pipeline can use it independently.
Challenges we ran into
The hardest architectural decision was keeping the LLM completely out of the financial verdict loop.
The temptation is to let Gemini evaluate cost and make the approval decision — it feels more "agentic." But LLMs hallucinate arithmetic. Giving an LLM authority over budget decisions in a production environment is how you recreate exactly the problem you were trying to solve.
The separation of concerns — deterministic code governs the policy, AI solves the remediation — required deliberate architectural discipline to maintain throughout the build.
Accomplishments that we're proud of
A verifier that can genuinely disagree with you. The tamper detection does not just show "verified" — it recomputes the entire SHA-256 chain independently and breaks on a single mutated character.
Gemini performing true multimodal vision on actual rendered frames, not text descriptions of frames.
Extracting
hashledgeras a reusable open-source primitive alongside the hackathon submission.
What we learned
Building the infrastructure layer — not the app.
StudioGate is not a dashboard that monitors render costs. It is the gate that render jobs cannot bypass. That architectural position — sitting between the dispatcher and the cluster — is what makes every other feature meaningful.
What's next for StudioGate
- Native integration with real job dispatchers: AWS Deadline, Pixar's Tractor, and SideFX Houdini PDG.
- Multi-tenant studio isolation with per-project budget namespaces in ClickHouse.
- Real-time Slack and PagerDuty escalation when jobs are blocked during active production windows.
Honesty Table
| What's Real | What's Simplified | What's Out of Scope |
|---|---|---|
| Deterministic policy engine with 37 passing unit tests | GPU telemetry is synthetically seeded, not streamed from a physical render farm | Integration with real dispatchers: AWS Deadline, Tractor, PDG |
| SHA-256 hash-chain with live tamper verification | Budget ceiling ($500) is a demonstration threshold, not production-calibrated | Multi-tenant studio isolation and per-project namespaces |
| Live ClickHouse Cloud queries over 50,000 real rows | Gemini remediation operates on structured context plus static render frames | Production secrets management beyond .env |
| Real Gemini ADK multimodal API calls with image input | ||
| Empirically measured benchmark latency, not estimated |
Built With
- clickhouse-cloud
- cryptography
- fastapi
- google-adk
- google-gemini
- javascript
- mergetree
- numpy
- pil
- python
- sha-256
- tailwind-css
- vercel
- webgl
Log in or sign up for Devpost to join the conversation.