A Zero‑Trust autonomous agent runtime built on gVisor, OPA Gatekeeper, and hardened Kubernetes primitives. Contain every agent. Trust no image. Enforce every boundary.
LLM‑powered agents can call APIs, write code, and mutate infrastructure. Without strict runtime boundaries, they can accidentally exfiltrate data, escalate privileges, or talk to systems they were never meant to touch.
Secure Agent Gateway is designed to be the hardened perimeter for these agents — a Zero‑Trust execution environment that treats every agent like untrusted code until proven otherwise.
The gateway sits between external callers and internal agent runtimes, enforcing strict boundaries at every layer: ingress, runtime, supply chain, secrets, and egress.
User / Client
↓
Ingress (NGINX / Envoy)
↓
Secure Agent Gateway (gVisor + OPA)
↓
NetworkPolicy (egress allowlist)
↓
Internal ML API / Database Proxy
Control Plane:
- OPA Gatekeeper (admission policies)
- External Secrets Operator (cloud secrets)
Cloud Secrets:
- AWS Secrets Manager
- GCP Secret Manager
- Azure Key Vault
gVisor sandboxing, seccomp RuntimeDefault, non‑root users, and read‑only root filesystems.
Agents run in a syscall‑restricted environment that prevents container breakout.
Immutable image tags, registry allowlists, and Cosign signature verification ensure only trusted, signed images are admitted to the cluster.
OPA Gatekeeper enforces runtime class, resource limits, privilege escalation, egress restrictions, and filesystem constraints before any Pod is created.
External Secrets Operator integrates with AWS, GCP, and Azure, keeping secrets out of manifests and in dedicated secret stores.
Hardened ingress and strict egress allowlists ensure agents only talk to the internal services they’re explicitly allowed to reach.
Helm charts, OPA policies, and GitOps layouts are designed for ArgoCD, Flux, and other controllers, making security part of your delivery pipeline.
Secure Agent Gateway ships as a Helm chart with a full OPA policy suite and documentation site. You can deploy it into an existing Kubernetes cluster and start enforcing Zero‑Trust boundaries around your agents immediately.
Clone the repo, install the chart, apply the policies, and wire your agents through the gateway.