Skip to content

Install the Platform (Agent Guide) ​

This guide is for coding agents. It explains how to install and uninstall the Zelkor Community Edition platform on an existing Kubernetes cluster.

Zelkor's core advantage: bring the agent you already wrote; it is sandboxed — it can't break out, reach unauthorized data or networks, its prompts are verified, budget controlled, and it is under observation.

Prerequisites ​

  • kubectl configured and pointing to the target cluster.
  • helm installed.
  • A valid LLM provider API key (e.g., OPENAI_API_KEY).
  • Target hostnames for the agent protocol and Langfuse UI.

Install (Evaluation) ​

To install the platform for evaluation (in-cluster-basic topology, no operators), use the quickstart script. This is suitable for testing and development.

bash
OPENAI_API_KEY=sk-... ./scripts/install-quickstart.sh \
  --namespace zelkor

The script has built-in localhost defaults (like agents.<namespace>.zelkor.local) for local evaluation. If you want to use real domains, provide --hosts-agents and --hosts-langfuse. The script will generate passwords and output the Envoy dataplane services.

Install (Production) ​

To install the platform in a production shape (operator-cr, HA, NetworkPolicies), use the production script. This requires real DNS names (not *.localhost).

bash
OPENAI_API_KEY=sk-... ./scripts/install-production.sh \
  --hosts-agents agents.example.com \
  --hosts-langfuse langfuse.example.com \
  --jwt-issuer "https://your-idp.example.com" \
  --jwt-audience "zelkor-platform" \
  --jwks-file "./path/to/jwks.json" \
  --namespace zelkor

If you need to skip operator installation (operators already present on the cluster), pass --skip-operators.

Set storage and sandbox to the cluster you have. Empty databases.*.storage.storageClass uses the cluster default; replica counts in the production profile need that class on enough nodes. Pin security.sandbox.nodes.selector to nodes that have RuntimeClass gvisor.

The installer prints the Envoy dataplane Service. A layered edge (Traefik, existing Ingress) must send Host-preserving traffic to that Service. Do not put another ClusterIP in Endpoints.

Later Helm upgrades that set workspace.models must pass the provider key again (--set-file) or omit apiKey so an empty overlay does not wipe it.

Note on JWT Issuers: Production installs strictly require a JWT issuer. If you are deploying an isolated system without an external IdP (like Okta or Entra ID), you can deploy a lightweight internal OIDC provider (like Keycloak) to your cluster, or use a Helm override to enable Zelkor's native localSigning fallback (see Tenant Reference for details). --jwt-issuer must match token iss. Prefer --jwks-file over an in-cluster JWKS URL. See JWT rejected (401).

Uninstall ​

To remove the Zelkor platform Helm release from the cluster:

bash
./scripts/uninstall.sh --namespace zelkor

This removes the platform release but leaves Envoy Gateway and operators intact. --purge-gateway and --purge-operators remove those components only when Zelkor recorded them in the cluster ownership ConfigMap (it skips a gateway another team installed).

bash
./scripts/uninstall.sh --namespace zelkor --purge-gateway --purge-operators

To also delete the namespace after uninstalling, append --delete-namespace.

Next Steps ​