Skip to content

Documentation ​

Zelkor is a self-hosted runtime for AI agents on Kubernetes. You set a model, a tool, and an agent; those same objects run from the laptop Community Edition install to a shared cluster. Bring the agent you already wrote; it is sandboxed — it can't break out, reach unauthorized data or networks, its prompts are verified, budget controlled, and it is under observation; tenants stay isolated (the agent cannot pick another tenant, see the tenant hop).

Editions ​

EditionWhat you get
Community EditionSelf-hosted runtime in this repository (gateway, tools, sandbox, traces)
ProSSO, team controls (budgets and approvals), production HA / GitOps
EnterpriseIsolation and compliance on Pro (hardware sandbox, mTLS, retained audit, BAA)

Start with Community Edition. Pro and Enterprise layers sit on the same platform shape.

Get started ​

PageJob
Local QuickstartInstall CE on kind, call a model, open a trace
Root READMEProduct overview and three-command install

Install ​

PageJob
Install on an Existing ClusterEvaluate CE via Helm on a shared cluster
Production InstallDeploy the highly available shape of CE with HA operators
UninstallRemove the platform from your cluster
UpgradeUpgrade the platform chart safely
Customize GuardrailsAdd custom NeMo safety policies
Gateway TopologiesHow Envoy Gateway integrates with your cluster

Agents and examples ​

PageJob
Install the Platform (Agent Guide)How coding agents install/uninstall the platform
Deploy an Agent (Agent Guide)How coding agents deploy/remove customer agents
Use the zelkor CLIEnv targets, deploy, run, logs, doctor
Register extra MCP backendsBYO ClusterIP MCP on the unified gateway
FinServe exampleOptional reference agents (not required to learn the platform)

Reference ​

PageJob
Add LLM providers and modelsHelm overlays for AI Gateway backends and model ids
Helm values referenceplatform / workspace / workload namespaces and schema
Hosts and Routinggateway.hosts.* vs internal ClusterIP names
Worker EnvironmentInjected env vars (OPENAI_BASE_URL, MCP_URL, OTEL)
MCP Tools ReferenceTool prefixes, extraBackends fields, and list mechanics
Agent ProtocolFront-door paths, graph ID matching, and fallbacks
TenantsClaims, org map, filters vs forwarded, zelkor token mint fields
Platform LoggingStdout JSON structure, levels, and environment variables

Architecture ​

PageJob
Architecture HubMap of all hops, components, and trust boundaries
Request PathHow a client call reaches the model
Network BoundariesWho may talk to whom inside the cluster
Sandbox IsolationWhere generated code executes
MCP GovernanceHow a tool call is isolated and authenticated
Run TraceWhat one run looks like in Langfuse
Drop-In Agent ContractHow Zelkor sandboxes and governs your agent (Intercept, Wrap, MCP)
Envoy Graph RoutingHow Envoy routes incoming calls to the correct agent deployment
North-South ExposureWhat Zelkor publishes to the internet versus what stays inside the cluster
Tenant IsolationHow one tenant identity is applied on a run
Agent DatastoresStateful infrastructure (Postgres, Qdrant) and BYO options

Troubleshooting (KB) ​

PageJob
Knowledge BaseIndex of known issues and fixes
Vertex gemini-* unknown backendFix AI Gateway 500 when Vertex auth rotation skips the backend
JWT rejected (401)Token iss vs Helm issuer and JWKS fetch
POST /runs/wait 422Body must include assistant_id
AI Gateway route_not_foundEmpty provider apiKey deleted the route

Read Install on an Existing Cluster and Production Install when you are ready to move off kind.