Install AgentFleetGateway and send your first request.
This guide takes a platform team from the versioned release bundle to a healthy control plane and a governed agent request.
1. Confirm prerequisites#
- An existing AKS, EKS, or GKE cluster running Kubernetes 1.27 or later, with permission to install CustomResourceDefinitions.
- Helm 3 and
kubectlconfigured for the target cluster. - The
az,aws, orgcloudCLI when your platform team has not already supplied a kubeconfig context. - The AgentFleetGateway release bundle provided during onboarding and access to its image registry.
- An enforcing Kubernetes NetworkPolicy provider when using the protected model path.
Connect kubectl to the managed cluster you intend to validate:
az aks get-credentials \
--resource-group <resource-group> \
--name <cluster>
aws eks update-kubeconfig \
--region <region> \
--name <cluster>
gcloud container clusters get-credentials <cluster> \
--region <region> \
--project <project>
kubectl config current-context
kubectl cluster-info
kubectl get nodes
Your onboarding materials contain the Helm chart, CRDs, versioned image values, checksums, and example resources used below. Deployment profiles are included inside the chart package.
2. Verify the release bundle#
Use the checksum and signature instructions supplied with your release before installing it. Keep the digest-pinned image values with the chart so Kubernetes pulls the reviewed images rather than mutable tags.
sha256sum --check SHA256SUMS
tar -xzf agentfleet-<version>.tgz
ls agentfleet/Chart.yaml \
agentfleet/profiles/local-durable.yaml \
agentfleet-images.values.json \
crds/ examples/
3. Configure private registry access#
Skip this step when your cluster already has access through workload identity or a platform-managed registry integration.
kubectl create namespace agentfleet-system
kubectl create secret docker-registry agentfleet-registry \
--namespace agentfleet-system \
--docker-server=<private-registry> \
--docker-username=<username> \
--docker-password=<access-token>
4. Install the CRDs and control plane#
For a guided evaluation on your managed cluster, start with local-durable. It enables policy, Context, Approval, Console, and a single-node PostgreSQL database with sample rules for the supplied evaluation agents.
kubectl apply -f crds/
helm upgrade --install agentfleet ./agentfleet \
--namespace agentfleet-system --create-namespace \
-f agentfleet/profiles/local-durable.yaml \
-f agentfleet-images.values.json \
--set global.imagePullSecrets[0].name=agentfleet-registry
local-durable is an evaluation shape, not a production database. For shared AKS, EKS, or GKE environments, layer enterprise-baseline with external PostgreSQL and your own policy rules by following Install with Helm. Add mesh-ready for Istio or protected-path for managed workload identity and router-only model egress.
5. Verify service readiness#
kubectl get pods -n agentfleet-system
kubectl port-forward -n agentfleet-system \
svc/agentfleet-gateway 8080:8080
In another terminal, check the dependency-aware readiness endpoint:
curl -s http://127.0.0.1:8080/readyz
The response should report ready. Optional modules may report disabled; required modules must not report unavailable.
6. Onboard an agent#
Review the supplied evaluation manifests before applying them. They create deterministic agents, capability routes, and policies for the retail and enterprise-it tenants.
kubectl create namespace agentfleet-demo
kubectl apply -f examples/demo-agents/manifests/
kubectl get agents,agentroutes,agentpolicies -n agentfleet-demo
7. Send a governed request#
curl -s http://127.0.0.1:8080/v1/run \
-H 'Content-Type: application/json' \
-d '{"tenant":"retail","capability":"refund-processing",
"input":{"message":"check refund eligibility for order 123"}}'
The response identifies the selected agent and includes routing and policy metadata. A policy_denied response means the control plane is enforcing policy but the supplied rule does not match the request.
8. Continue the rollout#
- Verify your install and dependency readiness in more detail.
- Write your authorization policy before onboarding production traffic.
- Review the protected model path before enabling managed workload protection.
- Review availability requirements with your AgentFleet contact.