Skip to content

About

Self-hosted agent runtime on your Kubernetes cluster. Bring the agent you already wrote; it is sandboxed — it can't break out, reach unauthorized data or networks; prompts are verified, budget controlled, and it is under observation; tenants stay isolated.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Repository files navigation

Zelkor Platform

License Chart

You get a self-hosted agent runtime on your Kubernetes cluster: bring the agent you already wrote; it is sandboxed — it can't break out, reach unauthorized data or networks, its prompts are verified, budget controlled, and it is under observation; tenants stay isolated.

You configure three things — a model, a tool, and an agent. The laptop install and a shared cluster use the same objects and the same Helm charts. Community Edition is Apache-2.0 and runs from this repository without a sales step.

Run Community Edition on your laptop

Needs Docker running, kind, helm, kubectl, and one LLM provider key.

git clone https://github.com/devopssquaddev/zelkor-platform.git
cd zelkor-platform
OPENAI_API_KEY=sk-... ./install.sh

./install.sh creates a local kind cluster, installs Zelkor Community Edition (chart 2.3.1), and prints URLs when it finishes. Full prerequisites, other providers, and the first verification call: Local Quickstart.

What you set

You declare Platform job
Model Routes chat and embeddings through one gateway; injects the upstream key from a cluster secret
Tool Exposes tools over MCP (Model Context Protocol) — SQL, vectors, sandbox, your own backends — without putting secrets in agent code
Agent Deploys your LangGraph or Deep Agents workload; you run it and open the trace

After the local install, point the zelkor CLI at the cluster, zelkor deploy your project, zelkor run, then open the trace UI the install prints (Langfuse). A worked demo lives under examples/finserve/ if you want a sample agent — it is not required to learn the platform.

What wraps the agent you already wrote:

What wraps the agent you already wrote

Those four arrows are the only paths out of the agent. It cannot reach another network, another tenant’s data, or run generated code in its own process. The run, the tools, and the trace share one verified tenant identity; the agent cannot choose a different tenant. Full hops: Architecture Hub and Tenant Isolation.

Editions

Edition What you get
Community Edition The self-hosted runtime in this repo: gateway, tools, sandbox, traces, Helm install
Pro SSO, team controls (budgets and approvals), and team GitOps on top of CE
Enterprise Isolation and compliance on Pro: hardware sandbox, mTLS, retained audit, BAA

CE is enough to evaluate and to run production-shaped installs. Pro and Enterprise add control-plane and compliance layers — not a different product story.

🏢 For Enterprise — isolation, audit retention, and BAA on the same platform shape. Start with Local Quickstart; talk to us when CE is running on a shared cluster.

Docs

Start here Job
Local Quickstart Install CE on kind and prove a model call + a trace
Documentation index Map of every published page
zelkor CLI Point at a cluster, deploy your agent, run, inspect
FinServe example Optional reference agents on top of the platform

About

Self-hosted agent runtime on your Kubernetes cluster. Bring the agent you already wrote; it is sandboxed — it can't break out, reach unauthorized data or networks; prompts are verified, budget controlled, and it is under observation; tenants stay isolated.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Contributors

Languages