Drop-In Agent Contract
Zelkor’s core advantage is "Bring Your Own Agent, We Provide the Armor." You drop your LangChain, LangGraph, or Aegra agent onto the platform, and Zelkor sandboxes it without requiring you to rewrite your code.
The agent is sandboxed across multiple dimensions: it cannot break out of its runtime, it cannot reach unauthorized data or networks, its prompts are verified, its budget is controlled, and every action is under observation; tenants stay isolated (the agent cannot pick another tenant).
The Three Planes of Governance
Zelkor applies three planes of governance to your agent. Only Intercept and Wrap require zero source changes. MCP is an opt-in tool protocol.
---
config:
theme: neutral
---
flowchart TB
subgraph Wrap [Aegra Wrap]
Agent[Agent Worker\nClusterIP]
end
subgraph Intercept [Envoy AI Gateway]
AIGateway[AI Gateway /v1\nClusterIP]
NeMo[NeMo Guardrails\nClusterIP]
end
subgraph MCPPlane [MCP Gateway]
MCP[Native & Extra Tools\nClusterIP]
end
Client[Client] -- "Agent Protocol" --> Agent
Agent -- "LLM Calls (/v1)" --> AIGateway
AIGateway <--> NeMo
Agent -- "Tool Calls" --> MCP
Who may talk to whom: The agent is wrapped by Aegra, its LLM calls are intercepted by the AI Gateway, and its tools are governed by MCP.
1. Aegra Wrap (Serve the Graph)
The wrap plane serves your graph and provides the runtime sandbox.
- Deploy Unit: Your agent is packaged as an immutable image (
FROM ghcr.io/devopssquaddev/zelkor-aegra) and deployed as a ClusterIP service. - Identity & Isolation: Tenant authentication happens at the front door. The wrap injects the tenant ID into the graph's environment and thread state.
- Environment: The wrap injects
OPENAI_BASE_URL,OPENAI_API_KEY(a consumer key, not the real provider key), andMCP_URLinto the pod. - Network Sandbox: NetworkPolicies drop outbound traffic. The agent pod cannot reach databases or the internet directly—only the platform gateways.
2. Intercept (Envoy AI Gateway)
The intercept plane governs all LLM text generation.
- No Keys on the Agent: Real provider API keys stay on the AI Gateway. The agent only holds a consumer key.
- Prompt Verification: Traffic to
/v1/chat/completionsis routed through NeMo Guardrails to intercept, check, and verify interactions outside the agent's control. - Budget & Observation: The gateway enforces rate limits, tracks spend, and emits OpenTelemetry traces to Langfuse.
3. MCP (Tool Execution)
The Model Context Protocol (MCP) plane governs how the agent executes infrastructure tasks (SQL, vectors, sandbox) and accesses customer SaaS tools.
- Data Sandbox: Tools are called through the platform MCP gateway with strict tenant identity. The agent cannot bypass these controls to access other tenants' data.
- Mode A (Advertise): If your agent already speaks MCP, it simply calls the injected
MCP_URL. - Mode B (Inject): Zelkor can dynamically inject MCP tools into your compiled LangChain/LangGraph agent at startup, granting it governed access to Postgres, Qdrant, or your extra backends without source changes.
Editions as Layers
These planes form the base sandbox. Zelkor editions build upon this foundation:
- Community Edition: The self-hosted runtime providing the base sandbox (intercept, wrap, MCP).
- Pro: Adds SSO, team controls (budgets and approvals), and production HA / GitOps.
- Enterprise: Adds strict isolation and compliance on Pro (hardware sandbox, mTLS, retained audit, BAA).