Skip to content

Request Path ​

This page details how an external chat or run request flows through Zelkor to the agent, and how the agent reaches the model provider.

The core advantage is enforced on this path: the agent you already wrote is sandboxed, and provider keys stay on the gateway.

How a client call reaches the model: The call is routed to the agent, which then makes an intercepted call through the AI Gateway.

---
config:
  theme: neutral
---
flowchart LR
  Client[Client / User]
  Envoy[Envoy Gateway\nGateway]
  Agent[Agent Worker\nClusterIP]
  AIGateway[AI Gateway /v1\nClusterIP]
  NeMo[NeMo Guardrails\nClusterIP]
  Provider[Model Provider\nExternal]

  Client -- "Chat / Run Request" --> Envoy
  Envoy -- "Route by X-Graph-ID" --> Agent
  Agent -- "LLM Call (Consumer Key)" --> AIGateway
  AIGateway <-->|"Check Policies"| NeMo
  AIGateway -- "Inject Real Key" --> Provider

The Boundary ​

You deploy the Agent and configure the Model. The platform generates the Envoy HTTPRoutes, the AI Gateway intercept, and the NeMo policies.

The agent is never given the real provider key (e.g., your actual OpenAI API key). It is injected with a local consumer key (OPENAI_API_KEY) and its traffic is forced to OPENAI_BASE_URL pointing at the internal AI Gateway.

The AI Gateway performs rate limiting, applies guardrails via NeMo, injects the real provider credentials from a Kubernetes Secret, and forwards the request to the upstream model provider.