The building blocks of a governed agent fleet.
AgentFleetGateway separates agent identity, route selection, policy decisions, scheduling, protected model access, context, and evidence.
AgentKubernetes resource describing a deployable or external agent, including runtime, owner, tenant, endpoint, capabilities, models, tools, and status.
AgentRouteMaps intent or capability to eligible agents with priority and enablement controls.
AgentPolicyDefines allow, deny, and approval-required decisions across model, tool, region, cost, and audit constraints.
GatewayNormalizes incoming requests, resolves candidates, applies policy, selects a target, invokes the agent, and emits evidence.
RegistryMaintains queryable agent metadata, route inventory, and health information.
SchedulerRanks eligible agents deterministically and explains selection decisions.
Model RouterNormalizes provider access, enforces verified workload identity for protected callers, holds provider credentials, and records token, cost, and comparison evidence.
GuardOptional service for deterministic model input and output inspection on configured tenant and namespace bindings. Learned detection is not enabled as a product default.
Protected workloadA managed agent in a labeled namespace with a dedicated ServiceAccount, projected token, router-only egress, credential-free pod, and suspension control.
ContextOptional module for stateless, metadata-only, or full-history conversation retention.