Profiles
Nine curated value sets for the situations people actually install into. A profile is a starting point, not a lock — every key it sets can still be overridden.
Using a profile#
Extract the signed chart package first; its profiles/ directory contains the value sets shown here.
tar -xzf agentfleet-<version>.tgz
helm install agentfleet ./agentfleet \
--namespace agentfleet-system --create-namespace \
-f agentfleet/profiles/enterprise-baseline.yaml \
-f agentfleet-images.values.json
Profiles compose. Layer a second file to extend a base — later files win:
helm install agentfleet ./agentfleet \
-f agentfleet/profiles/enterprise-baseline.yaml \
-f agentfleet/profiles/enterprise-postgres.yaml \
-f agentfleet-images.values.json
Render any profile without installing it:
helm template agentfleet ./agentfleet \
-f agentfleet/profiles/secure-production.yaml \
-f agentfleet-images.values.json
Evaluation#
| Profile | Storage | Policy | Use it when |
|---|---|---|---|
| local-light | memory | off | Fastest path on a disposable Kubernetes evaluation cluster. Nothing survives a restart and modules stay off, so you see the routing path with the least moving parts. |
| local-durable | bundled PostgreSQL | enforce | Local evaluation that survives restarts, with policy actually enforcing. Ships sample rules covering the demo agents so traffic flows. |
| demo-observability | in-memory | off | Adds Prometheus, Grafana, and a ClickHouse audit sink so you can see dashboards and query evidence — see Operations. Ships policy rules but does not turn policy on at the gateway; layer with local-durable for enforcement and Postgres together. |
local-durable runs a single-replica PostgreSQL StatefulSet for convenience. It is not an HA
shape and is not meant to be one. Point production installs at a managed database.
Production#
| Profile | Storage | Policy | Use it when |
|---|---|---|---|
| enterprise-baseline | memory | enforce | The starting point for a real cluster: two replicas, resource requests, policy enforcing. Add storage and rules on top. |
| enterprise-postgres | external PostgreSQL | inherited | Layer over enterprise-baseline to make registry and context durable against your own database. |
| secure-production | external PostgreSQL | enforce | The hardened preset: tenant authorization enforced, auto-migration off, no bundled database, no sample rules. |
| mesh-ready | inherited | inherited | Layer on when running under Istio with strict mTLS. Adds mesh labels, annotations, and the conformance assets. |
| context-audit | inherited | inherited | Layer on to turn on conversation history and request audit emission without changing anything else. |
| protected-path | inherited | enforce | Layer on for managed agent namespaces that require workload identity, router-only model egress, server-side provider credentials, optional Guard inspection, suspension, and protected-path evidence. Requires an enforcing CNI. |
enterprise-baseline and secure-production set policy.rules to an
empty map on purpose, so they fail closed. A profile that shipped a working allow list would be shipping
somebody else's authorization decisions. Author your own before sending traffic.
Checking what a profile does#
Profiles are plain values files in the extracted chart's agentfleet/profiles/ directory. To see exactly what one changes,
diff its rendered output against the defaults:
helm template agentfleet ./agentfleet \
-f agentfleet-images.values.json > /tmp/default.yaml
helm template agentfleet ./agentfleet \
-f agentfleet/profiles/secure-production.yaml \
-f agentfleet-images.values.json > /tmp/secure.yaml
diff /tmp/default.yaml /tmp/secure.yaml