Enterprise early access is open. Request access

Docs Concepts Protected model path

Protected model access for managed Kubernetes agents.

The optional protected path makes the Model Router the controlled model-access boundary for AgentFleet-managed agents in explicitly protected namespaces.

What the protected path covers#

Designed for managed agent namespaces

The end-to-end path combines workload identity, controlled egress, provider credential isolation, policy, optional Guard inspection, suspension, and audit records. Confirm enforcement with the CNI, service-mesh mode, and managed Kubernetes platform used by your deployment.

Protected request path#

  1. The operator gives each managed agent a dedicated ServiceAccount and a short-lived, audience-bound projected token.
  2. An operator-owned default-deny NetworkPolicy permits model traffic only to the Model Router, plus explicitly approved platform destinations.
  3. The Model Router validates the token with Kubernetes TokenReview and binds the verified ServiceAccount to the Registry tenant and agent identity.
  4. Policy and approval controls run before provider access. Configured Guard bindings inspect model input and output.
  5. The Model Router injects server-side provider credentials, calls the approved provider, and emits payload-minimized audit, usage, latency, and cost evidence.

Controls and ownership#

Workload identityDedicated ServiceAccounts and rotating projected tokens identify managed agents without static application credentials.
Egress enforcementDefault-deny policies block direct provider access when the cluster CNI enforces Kubernetes NetworkPolicy.
Credential boundaryProvider credentials remain at the Model Router and are not mounted into protected agent pods.
GuardOptional, deterministic input/output inspection is enabled per tenant and namespace binding. Findings are minimized before audit and usage projection.
Kill switchspec.suspended scales the agent to zero, removes it from Gateway routing, and causes workload model calls to fail with agent_suspended.
VerificationDeployment checks confirm mediated model access, direct-egress denial, identity rejection, suspension, credential-free pods, and payload-free audit.

Install and protect a namespace#

Use the profile only with an enforcing CNI such as Calico, Cilium, GKE Dataplane V2, or a supported managed-cloud network-policy implementation. The Helm enforcement probe fails installation when default-deny egress is not active.

helm upgrade --install agentfleet ./agentfleet \
  --namespace agentfleet-system --create-namespace \
  -f agentfleet/profiles/protected-path.yaml \
  -f agentfleet-images.values.json

kubectl label namespace team-agents agentfleet.io/protection=managed

Plain Kubernetes is the baseline. Istio remains an optional overlay, not a requirement for the protected path.

Suspend and resume an agent#

kubectl patch agent refund-agent -n team-agents --type=merge \
  -p '{"spec":{"suspended":true}}'

kubectl patch agent refund-agent -n team-agents --type=merge \
  -p '{"spec":{"suspended":false}}'

The propagation target is 30 seconds. Registry state refreshes at the Model Router on a shorter interval so a published suspension normally reaches model access within about five seconds.

Security boundary#

  • Protection applies only to namespaces labeled agentfleet.io/protection=managed after the network-policy enforcement probe passes.
  • External agents, unlabeled namespaces, non-enforcing CNIs, and cluster administrators remain outside this boundary.
  • Guard does not claim complete prompt-injection prevention, factuality, or universal content safety.
  • Guard provides deterministic inspection for configured checks; learned classification is not enabled by default.

Review Architecture, Operations, and Availability before enabling this path for customer traffic.