Secure Agent Gateway

A Zero‑Trust autonomous agent runtime built on gVisor, OPA Gatekeeper, and hardened Kubernetes primitives. Contain every agent. Trust no image. Enforce every boundary.

Explore Architecture See Security Features Get Started
Why

Autonomous agents need real guardrails

LLM‑powered agents can call APIs, write code, and mutate infrastructure. Without strict runtime boundaries, they can accidentally exfiltrate data, escalate privileges, or talk to systems they were never meant to touch.

Secure Agent Gateway is designed to be the hardened perimeter for these agents — a Zero‑Trust execution environment that treats every agent like untrusted code until proven otherwise.

Architecture

Zero‑Trust runtime, from ingress to syscall

The gateway sits between external callers and internal agent runtimes, enforcing strict boundaries at every layer: ingress, runtime, supply chain, secrets, and egress.

User / Client
   ↓
Ingress (NGINX / Envoy)
   ↓
Secure Agent Gateway (gVisor + OPA)
   ↓
NetworkPolicy (egress allowlist)
   ↓
Internal ML API / Database Proxy

Control Plane:
- OPA Gatekeeper (admission policies)
- External Secrets Operator (cloud secrets)

Cloud Secrets:
- AWS Secrets Manager
- GCP Secret Manager
- Azure Key Vault
      
Security Features

Security, everywhere an agent can touch

Runtime Isolation

gVisor sandboxing, seccomp RuntimeDefault, non‑root users, and read‑only root filesystems. Agents run in a syscall‑restricted environment that prevents container breakout.

Supply Chain Integrity

Immutable image tags, registry allowlists, and Cosign signature verification ensure only trusted, signed images are admitted to the cluster.

Policy‑Driven Admission

OPA Gatekeeper enforces runtime class, resource limits, privilege escalation, egress restrictions, and filesystem constraints before any Pod is created.

Secret Hygiene

External Secrets Operator integrates with AWS, GCP, and Azure, keeping secrets out of manifests and in dedicated secret stores.

Network Boundaries

Hardened ingress and strict egress allowlists ensure agents only talk to the internal services they’re explicitly allowed to reach.

GitOps‑Friendly

Helm charts, OPA policies, and GitOps layouts are designed for ArgoCD, Flux, and other controllers, making security part of your delivery pipeline.

Get Started

Drop it into your cluster today

Secure Agent Gateway ships as a Helm chart with a full OPA policy suite and documentation site. You can deploy it into an existing Kubernetes cluster and start enforcing Zero‑Trust boundaries around your agents immediately.

Clone the repo, install the chart, apply the policies, and wire your agents through the gateway.

View on GitHub Read the Docs