Install the Platform (Agent Guide)
This guide is for coding agents. It explains how to install and uninstall the Zelkor Community Edition platform on an existing Kubernetes cluster.
Zelkor's core advantage: bring the agent you already wrote; it is sandboxed — it can't break out, reach unauthorized data or networks, its prompts are verified, budget controlled, and it is under observation.
Prerequisites
kubectlconfigured and pointing to the target cluster.helminstalled.- A valid LLM provider API key (e.g.,
OPENAI_API_KEY). - Target hostnames for the agent protocol and Langfuse UI.
Install (Evaluation)
To install the platform for evaluation (in-cluster-basic topology, no operators), use the quickstart script. This is suitable for testing and development.
bash
OPENAI_API_KEY=sk-... ./scripts/install-quickstart.sh \
--namespace zelkorThe script has built-in localhost defaults (like agents.<namespace>.zelkor.local) for local evaluation. If you want to use real domains, provide --hosts-agents and --hosts-langfuse. The script will generate passwords and output the Envoy dataplane services.
Install (Production)
To install the platform in a production shape (operator-cr, HA, NetworkPolicies), use the production script. This requires real DNS names (not *.localhost).
bash
OPENAI_API_KEY=sk-... ./scripts/install-production.sh \
--hosts-agents agents.example.com \
--hosts-langfuse langfuse.example.com \
--jwt-issuer "https://your-idp.example.com" \
--jwt-audience "zelkor-platform" \
--jwks-file "./path/to/jwks.json" \
--namespace zelkorIf you need to skip operator installation (operators already present on the cluster), pass --skip-operators.
Set storage and sandbox to the cluster you have. Empty databases.*.storage.storageClass uses the cluster default; replica counts in the production profile need that class on enough nodes. Pin security.sandbox.nodes.selector to nodes that have RuntimeClass gvisor.
The installer prints the Envoy dataplane Service. A layered edge (Traefik, existing Ingress) must send Host-preserving traffic to that Service. Do not put another ClusterIP in Endpoints.
Later Helm upgrades that set workspace.models must pass the provider key again (--set-file) or omit apiKey so an empty overlay does not wipe it.
Note on JWT Issuers: Production installs strictly require a JWT issuer. If you are deploying an isolated system without an external IdP (like Okta or Entra ID), you can deploy a lightweight internal OIDC provider (like Keycloak) to your cluster, or use a Helm override to enable Zelkor's native
localSigningfallback (see Tenant Reference for details).--jwt-issuermust match tokeniss. Prefer--jwks-fileover an in-cluster JWKS URL. See JWT rejected (401).
Uninstall
To remove the Zelkor platform Helm release from the cluster:
bash
./scripts/uninstall.sh --namespace zelkorThis removes the platform release but leaves Envoy Gateway and operators intact. --purge-gateway and --purge-operators remove those components only when Zelkor recorded them in the cluster ownership ConfigMap (it skips a gateway another team installed).
bash
./scripts/uninstall.sh --namespace zelkor --purge-gateway --purge-operatorsTo also delete the namespace after uninstalling, append --delete-namespace.
Next Steps
- Deploy a customer agent onto the platform using the Agent Deploy Guide.