MAQPNA

Product

Every agent action, governed.

MAQPNA is a runtime, not a framework. It sits underneath whatever agent you build and controls what that agent can reach, what it can do and what it leaves behind, on Kubernetes you run.

Isolate

A sandbox per session, at the boundary you choose.

Every run of an agent is a session in a fresh sandbox, created through the upstream kubernetes-sigs/agent-sandbox project. Pick the isolation per agent with a trust tier.

  • Default-deny NetworkPolicy per session: a sandbox reaches cluster DNS and the gateway, nothing else.
  • Non-root, read-only root filesystem, no Kubernetes service-account token in the sandbox.
  • Warm pools of pre-started sandboxes for fast session start, with the token bound late.
  • Snapshots to resume or fork a session; TTLs and idle suspend.
  • Browser and code-interpreter profiles with governed egress and execution.
tier-0gVisorUser-space kernel intercepts syscalls. For code interpreters and untrusted scripts.runtimeClass: gvisor
tier-1Kata Containers + FirecrackerA hardware-virtualised microVM per session. For build tools and browsers.runtimeClass: kata-fc
tier-2Confidential VMAMD SEV-SNP or Intel TDX encrypts memory; attestation required. For regulated data.runtimeClass: kata-qemu-snp

Identify

Every call carries who, what and on whose behalf.

The identity broker gives each session a short-lived, signed workload identity (SPIFFE-style), bound to its agent, trust tier, namespace and the person it acts for.

  • Ed25519-signed session tokens, verified at the gateway against the broker's public keys (JWKS).
  • The on-behalf-of user is in every token and every audit record.
  • Delegation for agent-to-agent (A2A) calls with a nested act chain and depth limits.
  • A token vault holds users' OAuth tokens outside the agent; the gateway injects credentials.
  • Admin API over OIDC single sign-on with roles: admin, approver, auditor, killswitch.
session identity (decoded)
{
  "sub": "spiffe://cluster.local/ns/team-a/agent/coder",
  "session": "asess-91d2",
  "tier": "tier-1",
  "obo": "[email protected]",
  "scope": "tools:github tools:kubernetes",
  "exp": /* minutes, not months */
}

Illustrative claims. Field names are simplified.

Govern

Policy per tool, per argument, default deny.

A policy is a list of rules. Each rule matches calls by server, tool, arguments and taint, and allows, denies or requires approval. No matching rule means the call is denied.

  • Typed argument conditions and globs, or Cedar and Rego for complex rules.
  • Rate limits per rule; budgets per session, agent, user and tenant with hard stops.
  • Model routes with allow-lists per agent and namespace, and model-for-data-class rules.
  • maqpna policy test suites, replay of real traffic against a new policy and eval scoring before rollout.
  • A sovereignty policy every session is admitted against: jurisdiction, registries, egress, attestation.
policy.yaml
kind: ToolPolicy
spec:
  defaultAction: deny
  rules:
    - name: read-only-tools
      tools: ["get_*", "list_*", "search_*"]
      action: allow
      maxCallsPerMinute: 120
    - name: production-writes-blocked
      tools: ["*"]
      argMatch: { namespace: "prod*" }
      action: deny
    - name: destructive-needs-human
      tools: ["delete_*", "deploy_*", "merge_*"]
      action: require_approval

Approve

A person decides when a rule says so.

A require_approval rule holds the call. Approving lets exactly that one call run. Pending approval is shown in violet everywhere: a person is needed, nothing is wrong.

  • Four-eyes approval that needs two different approvers.
  • Separation of duties: approvers cannot approve calls made on their own behalf.
  • User approval on their own device (CIBA) for the person the agent acts for.
  • Timeouts, notifier callbacks, and approvals in the console, MAQPNA Desk or maqpna approvals.
  • Sync mode holds the request; async mode returns at once and the SDK waits for the decision.
Held for approval payments.create_transfer
Session
team-a/payments-ops
On behalf of
[email protected]
Amount
€48,200.00
Rule
four-eyes above €10,000
Approvers
1 of 2 · [email protected]
ApproveDeny

Illustration of an approval in the console.

Protect

Data and secrets stay where they belong.

The gateway inspects what goes out and what comes back, and remembers when a session has read something it should not trust.

  • Data loss prevention (DLP): find and deny or redact keys and personal data in arguments, results and prompts.
  • Taint tracking: content from untrusted sources marks the session; later sensitive tools need approval or are denied.
  • Tool pinning: a tool whose definition changed after it was pinned (drift) is hidden and denied until reviewed.
  • Credential injection at the gateway: the agent never sees upstream keys.
  • Governed web fetch with domain policy, and governed memory stores with erasure certificates.
argument"note": "IBAN DE89 3704 0044 0532 0130 00, call Jan Novak"
forwarded"note": "IBAN [REDACTED:iban], call [REDACTED:person]"
Redacted · 2 findings · DLP

Illustrative values.

Stop

A kill switch that works in about a second.

Revoke an agent, a session, a user or a token across the installation. Running tool calls are cut off and the reason is recorded in the audit ledger.

  • maqpna kill at the gateway, or an AgentRevocation manifest for GitOps.
  • Suspend or terminate matching sessions; sandbox and token deleted on terminate.
  • If the revocation list is unavailable, calls are denied.
  • A dedicated killswitch role, separate from admin.
maqpna kill -h
# Revoke one agent in a namespace and terminate its sessions
maqpna kill --gateway "$GW" -n team-a --agent coder --reason "INC-123" --terminate
# The same as a manifest, for GitOps or when the gateway is unreachable
maqpna kill -n team-a --agent coder --reason "INC-123" --terminate --emit-yaml | kubectl apply -f -

From maqpna kill -h.

Prove

Evidence, not screenshots.

Every decision, approval, revocation and result is an append-only, hash-chained audit record with the policy and rule that made it. Anyone with the public key can verify that nothing was changed or removed.

  • Signed checkpoints of the ledger head; maqpna audit verify recomputes the chain.
  • Ship the ledger to S3-compatible write-once storage (WORM) with Object Lock, in your country.
  • Evidence bundles per session or period, and the DORA Art. 28 third-party register.
  • A session timeline, OpenTelemetry traces linked to records, and SIEM export.
  • Costs and usage exported in FOCUS, the FinOps cost-export format.

Illustration of the hash chain.

Operate

Built for day two.

Agents, policies and trust tiers are Kubernetes resources, so they live in Git. The maqpna CLI covers the whole lifecycle.

  • A Helm chart with dev, default and sovereign profiles; guides for AKS, EKS, GKE, OpenShift, k3s and kind.
  • preflight, install, upgrade check, rollback, doctor, smoke and status.
  • backup, restore and dr drill that reports recovery time and data-loss window.
  • A highly available gateway with PostgreSQL state, Prometheus alerts and three Grafana dashboards.
  • The MAQPNA Console in the browser, and MAQPNA Desk for approvals on the desktop.
  • maqpna preflight
  • maqpna install
  • maqpna upgrade check
  • maqpna doctor
  • maqpna status
  • maqpna smoke
  • maqpna backup
  • maqpna dr drill
  • maqpna keys rotate
  • maqpna audit verify
  • maqpna evidence
  • maqpna airgap
  • maqpna verify
  • maqpna support-bundle
  • maqpna costs

Open standards

Built on upstream, not around it.

MAQPNA builds on open projects and protocols, so your agents, tools and skills stay portable.

  • KubernetesCRDs, Helm, GitOps
  • agent-sandboxkubernetes-sigs sandbox primitive
  • gVisortier-0 isolation
  • Kata Containers + Firecrackertier-1 microVMs
  • Confidential Containerstier-2 and attestation
  • Model Context Protocoltools (MCP)
  • Agent2Agentagent-to-agent calls (A2A)
  • SPIFFE, OIDCworkload and human identity
  • OpenTelemetrytraces linked to records
  • Sigstore cosignsigned releases

See the gateway decide on your own agent.

Run your agent under a local MAQPNA in minutes, then move it to a cluster without changing its code.

curl -fsSL https://maqpna.com/install.sh | sh

No Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.