You get a self-hosted agent runtime on your Kubernetes cluster: bring the agent you already wrote; it is sandboxed — it can't break out, reach unauthorized data or networks, its prompts are verified, budget controlled, and it is under observation; tenants stay isolated.
You configure three things — a model, a tool, and an agent. The laptop install and a shared cluster use the same objects and the same Helm charts. Community Edition is Apache-2.0 and runs from this repository without a sales step.
Needs Docker running, kind, helm, kubectl, and one LLM provider key.
git clone https://github.com/devopssquaddev/zelkor-platform.git
cd zelkor-platform
OPENAI_API_KEY=sk-... ./install.sh./install.sh creates a local kind cluster, installs Zelkor Community Edition (chart 2.3.1), and prints URLs when it finishes. Full prerequisites, other providers, and the first verification call: Local Quickstart.
| You declare | Platform job |
|---|---|
| Model | Routes chat and embeddings through one gateway; injects the upstream key from a cluster secret |
| Tool | Exposes tools over MCP (Model Context Protocol) — SQL, vectors, sandbox, your own backends — without putting secrets in agent code |
| Agent | Deploys your LangGraph or Deep Agents workload; you run it and open the trace |
After the local install, point the zelkor CLI at the cluster, zelkor deploy your project, zelkor run, then open the trace UI the install prints (Langfuse). A worked demo lives under examples/finserve/ if you want a sample agent — it is not required to learn the platform.
What wraps the agent you already wrote:
Those four arrows are the only paths out of the agent. It cannot reach another network, another tenant’s data, or run generated code in its own process. The run, the tools, and the trace share one verified tenant identity; the agent cannot choose a different tenant. Full hops: Architecture Hub and Tenant Isolation.
| Edition | What you get |
|---|---|
| Community Edition | The self-hosted runtime in this repo: gateway, tools, sandbox, traces, Helm install |
| Pro | SSO, team controls (budgets and approvals), and team GitOps on top of CE |
| Enterprise | Isolation and compliance on Pro: hardware sandbox, mTLS, retained audit, BAA |
CE is enough to evaluate and to run production-shaped installs. Pro and Enterprise add control-plane and compliance layers — not a different product story.
🏢 For Enterprise — isolation, audit retention, and BAA on the same platform shape. Start with Local Quickstart; talk to us when CE is running on a shared cluster.
| Start here | Job |
|---|---|
| Local Quickstart | Install CE on kind and prove a model call + a trace |
| Documentation index | Map of every published page |
zelkor CLI |
Point at a cluster, deploy your agent, run, inspect |
| FinServe example | Optional reference agents on top of the platform |