Protected model access for managed Kubernetes agents.
The optional protected path makes the Model Router the controlled model-access boundary for AgentFleet-managed agents in explicitly protected namespaces.
What the protected path covers#
The end-to-end path combines workload identity, controlled egress, provider credential isolation, policy, optional Guard inspection, suspension, and audit records. Confirm enforcement with the CNI, service-mesh mode, and managed Kubernetes platform used by your deployment.
Protected request path#
- The operator gives each managed agent a dedicated ServiceAccount and a short-lived, audience-bound projected token.
- An operator-owned default-deny NetworkPolicy permits model traffic only to the Model Router, plus explicitly approved platform destinations.
- The Model Router validates the token with Kubernetes TokenReview and binds the verified ServiceAccount to the Registry tenant and agent identity.
- Policy and approval controls run before provider access. Configured Guard bindings inspect model input and output.
- The Model Router injects server-side provider credentials, calls the approved provider, and emits payload-minimized audit, usage, latency, and cost evidence.
Controls and ownership#
spec.suspended scales the agent to zero, removes it from Gateway routing, and causes workload model calls to fail with agent_suspended.Install and protect a namespace#
Use the profile only with an enforcing CNI such as Calico, Cilium, GKE Dataplane V2, or a supported managed-cloud network-policy implementation. The Helm enforcement probe fails installation when default-deny egress is not active.
helm upgrade --install agentfleet ./agentfleet \
--namespace agentfleet-system --create-namespace \
-f agentfleet/profiles/protected-path.yaml \
-f agentfleet-images.values.json
kubectl label namespace team-agents agentfleet.io/protection=managed
Plain Kubernetes is the baseline. Istio remains an optional overlay, not a requirement for the protected path.
Suspend and resume an agent#
kubectl patch agent refund-agent -n team-agents --type=merge \
-p '{"spec":{"suspended":true}}'
kubectl patch agent refund-agent -n team-agents --type=merge \
-p '{"spec":{"suspended":false}}'
The propagation target is 30 seconds. Registry state refreshes at the Model Router on a shorter interval so a published suspension normally reaches model access within about five seconds.
Security boundary#
- Protection applies only to namespaces labeled
agentfleet.io/protection=managedafter the network-policy enforcement probe passes. - External agents, unlabeled namespaces, non-enforcing CNIs, and cluster administrators remain outside this boundary.
- Guard does not claim complete prompt-injection prevention, factuality, or universal content safety.
- Guard provides deterministic inspection for configured checks; learned classification is not enabled by default.
Review Architecture, Operations, and Availability before enabling this path for customer traffic.