Skip to content

Helm, Kubernetes and EKS

  • api (control node), worker and ui deployments;
  • PostgreSQL as an optional bundled dependency, or an external database;
  • a migrations Job as a Helm hook;
  • NetworkPolicies with default deny and explicit egress;
  • PodSecurity restricted (non-root, read-only root file system, no privilege escalation);
  • HorizontalPodAutoscaler, PodDisruptionBudget and a ServiceMonitor for the Prometheus Operator;
  • ingress for nginx or the AWS Load Balancer Controller (ALB).
Terminal window
kubectl create namespace openagentix
kubectl -n openagentix create secret generic openagentix-secrets \
--from-literal=database-url='postgres://…' \
--from-file=audit-signing-key=./audit-ed25519.pem
helm install openagentix ./charts/openagentix -n openagentix -f values.yaml

Publishing the chart as a Helm repository and as an OCI artifact is on the roadmap.

database:
external: true
existingSecret: openagentix-secrets
auth:
oidc:
issuer: https://login.example.com/realms/main
clientId: openagentix
existingSecret: openagentix-oidc
ingress:
className: alb # or nginx
host: agents.example.com
networkPolicy:
enabled: true # default deny
egress:
- to: bedrock-vpc-endpoint
cidr: 10.0.12.0/24
ports: [443]
serviceAccount:
annotations:
eks.amazonaws.com/role-arn: arn:aws:iam::123456789012:role/openagentix-bedrock
  1. Create an IAM role for IRSA that trusts your cluster’s OIDC provider and the chart’s service account, with bedrock:InvokeModel on the allowed models.
  2. Annotate the service account with the role ARN (see above).
  3. Create a Bedrock VPC interface endpoint or set a proxy, and allow it in the network policy.
  4. Configure the Bedrock provider without any static keys.

From 0.2, the kubernetes-job runner starts one Job per run in the openagentix-runs namespace with its own service account (openagentix-worker), IRSA annotation and NetworkPolicy.