One shared kernel
Every container on a node shares the host kernel. A single kernel exploit in model-written code becomes a node compromise — and a path to every other tenant's data.
MAQPNA runs every agent session in an isolated, attested sandbox on your Kubernetes clusters. Each session gets a verifiable identity, and every tool call it makes is checked against policy and written to a tamper-evident audit ledger — in your jurisdiction, under your keys.
apiVersion: maqpna.com/v1alpha1
kind: Agent
metadata:
name: claims-triage
spec:
image: registry.eu.internal/agents/triage:1.4
tier: tier-2 # confidential VM, attested
policyRef: claims-tools
tools:
- name: case-db # MCP server, via gateway
---
apiVersion: maqpna.com/v1alpha1
kind: ToolPolicy
metadata:
name: claims-tools
spec:
defaultAction: deny
rules:
- name: read-cases
servers: ["case-db"]
tools: ["read_*"]
action: allow
maxCallsPerMinute: 60
- name: payouts
servers: ["case-db"]
tools: ["approve_payout"]
action: require_approval
Illustrative manifests. API group maqpna.com/v1alpha1 is pre-release and may change.
AI agents write and execute code nobody reviewed, call tools with real side-effects, and take instructions from whatever text lands in their context window. Running them like ordinary microservices leaves three gaps.
Every container on a node shares the host kernel. A single kernel exploit in model-written code becomes a node compromise — and a path to every other tenant's data.
Agents inherit service-account tokens and API keys that outlive the task. There is no way to prove which session, on which runtime, made a given call.
A prompt-injected agent can call any tool it can reach. Without a policy point in the path, "least privilege" and "who approved this?" are unanswerable.
Declare an Agent. The MAQPNA operator turns each AgentSession into an
upstream agent-sandbox Sandbox on the runtime its TrustTier requires,
issues it an identity, and routes every tool call through a policy-enforcing gateway.
Pick the boundary per agent: gVisor for untrusted code, Kata + Firecracker microVMs for hardware virtualisation, or confidential VMs (SEV-SNP / TDX) when even the host operator is out of scope.
Each session receives a short-lived, SPIFFE-style signed identity bound to its agent, tier and namespace. Confidential-tier identities are released only after attestation.
MCP and A2A calls pass through one policy point. ToolPolicy rules allow, deny, rate-limit
or require human approval — per agent, per tool, per argument.
Every decision is written as a hash-chained record — session, identity, tool, argument digest, policy, outcome — and can be shipped to WORM object storage you control.
| Tier | Runtime | RuntimeClass | Boundary | Typical use |
|---|---|---|---|---|
| tier-0 | gVisor (runsc) | gvisor |
User-space kernel intercepts syscalls | Code interpreters, data analysis, untrusted scripts |
| tier-1 | Kata Containers + Firecracker | kata-fc |
Hardware-virtualised microVM per session | Agents with build tools, browsers, broader syscall needs |
| tier-2 | Kata CoCo (SEV-SNP / TDX) | kata-qemu-snp |
Encrypted memory, remote attestation required | Regulated data, customer secrets, untrusted infrastructure |
Sovereignty is three questions: whose law applies, who can operate it, and who can technically reach the data. MAQPNA is built so the answer to all three can be you.
SovereigntyPolicy pins jurisdiction, registries and egressAn init agent collects SEV-SNP or TDX evidence; the attestation service checks it against your reference values (or a Trustee KBS) before any identity is minted.
The identity broker signs with keys you provision. Rotate them on your schedule; MAQPNA never generates production keys for you.
MAQPNA makes no outbound calls by default. The only egress is what you configure — and that is constrained by an allowlist.
Images, Helm chart, upstream manifests, SBOMs and checksums in one signed tarball, installable into a private registry with no internet access.
Ship the audit ledger to in-country S3-compatible storage with Object Lock (e.g. MinIO) for write-once retention.
Logs, policies, SBOMs and signed provenance that help you document oversight, traceability and supply-chain controls for your own conformity work.
Honest scope: MAQPNA gives you the technical controls and the evidence. Regulatory compliance depends on how you deploy and operate it — we don't claim certifications we don't have. Read the sovereignty guide →
Offer "agents as a service" on the Kubernetes you already run. CRDs, Helm, GitOps — no new control plane, no per-team sandbox snowflakes.
agent-sandbox under the hoodGet a real isolation boundary, a policy point you can review, and an audit trail you can hand to an auditor.
Banks, insurers, healthcare and public sector teams that need agents without handing data or control to a foreign cloud.
The runtime is open source. Commercial editions add support, hardened distributions and sovereign operations — never a hosted dependency.
Apache-2.0. For teams evaluating or running agents on their own.
For organisations running agents in production.
For regulated and public-sector deployments with strict jurisdictional requirements.
Spin up a local kind cluster with gVisor, install MAQPNA with Helm and watch a governed tool call land in the audit ledger.
# requires docker, kind, kubectl, helm
git clone https://github.com/maqpna/maqpna && cd maqpna
make quickstart # kind + gVisor + agent-sandbox + MAQPNA
make demo
Early access is by email — write to hello@maqpna.com. We don't use tracking or newsletter tools on this site.