Network Boundaries
Zelkor enforces zero-trust boundaries around your agent workload. It uses strict Kubernetes NetworkPolicies to ensure the agent cannot bypass governance.
The core advantage: your agent is sandboxed and cannot reach unauthorized data or dial out to the internet directly.
Who may talk to whom: NetworkPolicies drop all outbound traffic from the agent except to the platform gateways.
---
config:
theme: neutral
---
flowchart TB
subgraph Internet[Internet]
SaaS[External SaaS / APIs]
end
subgraph Datastores[Datastores Namespace]
Postgres[Postgres\nClusterIP]
Valkey[Valkey\nClusterIP]
end
subgraph Platform[Platform Namespace]
AIGateway[AI Gateway\nClusterIP]
MCPGateway[MCP Gateway\nClusterIP]
end
subgraph Worker[Worker Namespace]
Agent[Agent Pod\nClusterIP]
end
Agent -- "/v1 chat" --> AIGateway
Agent -- "MCP tools" --> MCPGateway
Agent -.-x|"BLOCKED"| SaaS
Agent -.-x|"BLOCKED"| Postgres
Agent -.-x|"BLOCKED"| Valkey
AIGateway --> SaaS
MCPGateway --> Postgres
The Boundary
You provide the Agent Code. The platform generates the NetworkPolicies and Gateways.
By default (security.networkPolicies.enabled: false), traffic is not restricted. When you enable NetworkPolicies in production, an agent pod cannot open a connection to the internet, nor can it talk directly to the underlying datastores (Postgres, Valkey, Qdrant). All its interactions must go through the platform's AI Gateway for LLM calls and the MCP Gateway for tool calls and data access. This guarantees that observability, guardrails, and tenant isolation cannot be bypassed.