Product
Every agent action, governed.
MAQPNA is a runtime, not a framework. It sits underneath whatever agent you build and controls what that agent can reach, what it can do and what it leaves behind, on Kubernetes you run.
Isolate
A sandbox per session, at the boundary you choose.
Every run of an agent is a session in a fresh sandbox, created through the upstream kubernetes-sigs/agent-sandbox project. Pick the isolation per agent with a trust tier.
- Default-deny
NetworkPolicyper session: a sandbox reaches cluster DNS and the gateway, nothing else. - Non-root, read-only root filesystem, no Kubernetes service-account token in the sandbox.
- Warm pools of pre-started sandboxes for fast session start, with the token bound late.
- Snapshots to resume or fork a session; TTLs and idle suspend.
- Browser and code-interpreter profiles with governed egress and execution.
runtimeClass: gvisorruntimeClass: kata-fcruntimeClass: kata-qemu-snpIdentify
Every call carries who, what and on whose behalf.
The identity broker gives each session a short-lived, signed workload identity (SPIFFE-style), bound to its agent, trust tier, namespace and the person it acts for.
- Ed25519-signed session tokens, verified at the gateway against the broker's public keys (JWKS).
- The on-behalf-of user is in every token and every audit record.
- Delegation for agent-to-agent (A2A) calls with a nested
actchain and depth limits. - A token vault holds users' OAuth tokens outside the agent; the gateway injects credentials.
- Admin API over OIDC single sign-on with roles:
admin,approver,auditor,killswitch.
{
"sub": "spiffe://cluster.local/ns/team-a/agent/coder",
"session": "asess-91d2",
"tier": "tier-1",
"obo": "[email protected]",
"scope": "tools:github tools:kubernetes",
"exp": /* minutes, not months */
}Illustrative claims. Field names are simplified.
Govern
Policy per tool, per argument, default deny.
A policy is a list of rules. Each rule matches calls by server, tool, arguments and taint, and allows, denies or requires approval. No matching rule means the call is denied.
- Typed argument conditions and globs, or Cedar and Rego for complex rules.
- Rate limits per rule; budgets per session, agent, user and tenant with hard stops.
- Model routes with allow-lists per agent and namespace, and model-for-data-class rules.
maqpna policy testsuites,replayof real traffic against a new policy andevalscoring before rollout.- A sovereignty policy every session is admitted against: jurisdiction, registries, egress, attestation.
kind: ToolPolicy
spec:
defaultAction: deny
rules:
- name: read-only-tools
tools: ["get_*", "list_*", "search_*"]
action: allow
maxCallsPerMinute: 120
- name: production-writes-blocked
tools: ["*"]
argMatch: { namespace: "prod*" }
action: deny
- name: destructive-needs-human
tools: ["delete_*", "deploy_*", "merge_*"]
action: require_approvalApprove
A person decides when a rule says so.
A require_approval rule holds the call. Approving lets exactly that one call run. Pending approval is shown in violet everywhere: a person is needed, nothing is wrong.
- Four-eyes approval that needs two different approvers.
- Separation of duties: approvers cannot approve calls made on their own behalf.
- User approval on their own device (CIBA) for the person the agent acts for.
- Timeouts, notifier callbacks, and approvals in the console, MAQPNA Desk or
maqpna approvals. - Sync mode holds the request; async mode returns at once and the SDK waits for the decision.
payments.create_transfer
- Session
- team-a/payments-ops
- On behalf of
- [email protected]
- Amount
- €48,200.00
- Rule
- four-eyes above €10,000
- Approvers
- 1 of 2 · [email protected]
Illustration of an approval in the console.
Protect
Data and secrets stay where they belong.
The gateway inspects what goes out and what comes back, and remembers when a session has read something it should not trust.
- Data loss prevention (DLP): find and deny or redact keys and personal data in arguments, results and prompts.
- Taint tracking: content from untrusted sources marks the session; later sensitive tools need approval or are denied.
- Tool pinning: a tool whose definition changed after it was pinned (drift) is hidden and denied until reviewed.
- Credential injection at the gateway: the agent never sees upstream keys.
- Governed web fetch with domain policy, and governed memory stores with erasure certificates.
"note": "IBAN DE89 3704 0044 0532 0130 00, call Jan Novak""note": "IBAN [REDACTED:iban], call [REDACTED:person]"Illustrative values.
Stop
A kill switch that works in about a second.
Revoke an agent, a session, a user or a token across the installation. Running tool calls are cut off and the reason is recorded in the audit ledger.
maqpna killat the gateway, or anAgentRevocationmanifest for GitOps.- Suspend or terminate matching sessions; sandbox and token deleted on terminate.
- If the revocation list is unavailable, calls are denied.
- A dedicated
killswitchrole, separate from admin.
# Revoke one agent in a namespace and terminate its sessions
maqpna kill --gateway "$GW" -n team-a --agent coder --reason "INC-123" --terminate
# The same as a manifest, for GitOps or when the gateway is unreachable
maqpna kill -n team-a --agent coder --reason "INC-123" --terminate --emit-yaml | kubectl apply -f -From maqpna kill -h.
Prove
Evidence, not screenshots.
Every decision, approval, revocation and result is an append-only, hash-chained audit record with the policy and rule that made it. Anyone with the public key can verify that nothing was changed or removed.
- Signed checkpoints of the ledger head;
maqpna audit verifyrecomputes the chain. - Ship the ledger to S3-compatible write-once storage (WORM) with Object Lock, in your country.
- Evidence bundles per session or period, and the DORA Art. 28 third-party register.
- A session timeline, OpenTelemetry traces linked to records, and SIEM export.
- Costs and usage exported in FOCUS, the FinOps cost-export format.
Illustration of the hash chain.
Operate
Built for day two.
Agents, policies and trust tiers are Kubernetes resources, so they live in Git. The maqpna CLI covers the whole lifecycle.
- A Helm chart with dev, default and sovereign profiles; guides for AKS, EKS, GKE, OpenShift, k3s and kind.
preflight,install,upgrade check,rollback,doctor,smokeandstatus.backup,restoreanddr drillthat reports recovery time and data-loss window.- A highly available gateway with PostgreSQL state, Prometheus alerts and three Grafana dashboards.
- The MAQPNA Console in the browser, and MAQPNA Desk for approvals on the desktop.
maqpna preflightmaqpna installmaqpna upgrade checkmaqpna doctormaqpna statusmaqpna smokemaqpna backupmaqpna dr drillmaqpna keys rotatemaqpna audit verifymaqpna evidencemaqpna airgapmaqpna verifymaqpna support-bundlemaqpna costs
Open standards
Built on upstream, not around it.
MAQPNA builds on open projects and protocols, so your agents, tools and skills stay portable.
- KubernetesCRDs, Helm, GitOps
- agent-sandboxkubernetes-sigs sandbox primitive
- gVisortier-0 isolation
- Kata Containers + Firecrackertier-1 microVMs
- Confidential Containerstier-2 and attestation
- Model Context Protocoltools (MCP)
- Agent2Agentagent-to-agent calls (A2A)
- SPIFFE, OIDCworkload and human identity
- OpenTelemetrytraces linked to records
- Sigstore cosignsigned releases
See the gateway decide on your own agent.
Run your agent under a local MAQPNA in minutes, then move it to a cluster without changing its code.
curl -fsSL https://maqpna.com/install.sh | shbrew install azmxai/maqpna/maqpnairm https://maqpna.com/install.ps1 | iexNo Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.