Open source · Kubernetes-native · Apache-2.0

The sovereign runtime for AI agents.

MAQPNA runs every agent session in an isolated, attested sandbox on your Kubernetes clusters. Each session gets a verifiable identity, and every tool call it makes is checked against policy and written to a tamper-evident audit ledger — in your jurisdiction, under your keys.

  • agent-sandbox
  • gVisor
  • Kata + Firecracker
  • Confidential Containers
  • MCP · A2A
agent.yaml
apiVersion: maqpna.com/v1alpha1
kind: Agent
metadata:
  name: claims-triage
spec:
  image: registry.eu.internal/agents/triage:1.4
  tier: tier-2            # confidential VM, attested
  policyRef: claims-tools
  tools:
    - name: case-db       # MCP server, via gateway
---
apiVersion: maqpna.com/v1alpha1
kind: ToolPolicy
metadata:
  name: claims-tools
spec:
  defaultAction: deny
  rules:
    - name: read-cases
      servers: ["case-db"]
      tools: ["read_*"]
      action: allow
      maxCallsPerMinute: 60
    - name: payouts
      servers: ["case-db"]
      tools: ["approve_payout"]
      action: require_approval

Illustrative manifests. API group maqpna.com/v1alpha1 is pre-release and may change.

The problem

Containers are not a trust boundary for LLM-generated code.

AI agents write and execute code nobody reviewed, call tools with real side-effects, and take instructions from whatever text lands in their context window. Running them like ordinary microservices leaves three gaps.

01 · Isolation

One shared kernel

Every container on a node shares the host kernel. A single kernel exploit in model-written code becomes a node compromise — and a path to every other tenant's data.

02 · Identity

Ambient, long-lived credentials

Agents inherit service-account tokens and API keys that outlive the task. There is no way to prove which session, on which runtime, made a given call.

03 · Governance

Ungoverned tool calls

A prompt-injected agent can call any tool it can reach. Without a policy point in the path, "least privilege" and "who approved this?" are unanswerable.

Agents as plain pods

  • runc on a shared kernel
  • Static secrets in env vars
  • Direct egress to any endpoint
  • Logs you hope nobody edited

Agents on MAQPNA

  • gVisor, microVM or confidential VM per session
  • Short-lived, workload-bound identity per session
  • Default-deny egress; tools only via the gateway
  • Hash-chained, append-only audit ledger
How it works

Isolation, identity, governance, evidence — as Kubernetes primitives.

Declare an Agent. The MAQPNA operator turns each AgentSession into an upstream agent-sandbox Sandbox on the runtime its TrustTier requires, issues it an identity, and routes every tool call through a policy-enforcing gateway.

MAQPNA architecture Inside your Kubernetes cluster, the MAQPNA operator provisions agent sessions as sandboxes in one of three trust tiers: gVisor, Kata Firecracker microVM, or confidential VM. The identity broker issues each session a short-lived identity; for the confidential tier it only does so after the attestation service has verified hardware evidence. Sandboxes have default-deny egress and reach tools only through the tool-call gateway, which verifies identity, evaluates ToolPolicy and writes every decision to the audit ledger before forwarding to MCP servers or A2A agents. YOUR KUBERNETES CLUSTER · YOUR JURISDICTION · YOUR KEYS maqpna-operator Agent · AgentSession · TrustTier Identity broker short-lived workload IDs Attestation SEV-SNP / TDX evidence gate AGENT SANDBOXES · DEFAULT-DENY tier-0 · gVisor user-space kernel tier-1 · microVM Kata + Firecracker tier-2 · confidential Kata CoCo · attested provisions identity Tool-call gateway 1 verify identity 2 evaluate ToolPolicy 3 rate-limit · approve 4 record decision 5 forward JWKS MCP servers tools · data · actions A2A agents · APIs allow-listed egress only Audit ledger hash-chained · WORM EVERY CALL: session · tier · tool · args hash decision · policy · prev-hash
Agents never talk to tools directly. Each sandbox can reach only cluster DNS and the gateway; the gateway decides, records, then forwards.

Three-tier isolation

Pick the boundary per agent: gVisor for untrusted code, Kata + Firecracker microVMs for hardware virtualisation, or confidential VMs (SEV-SNP / TDX) when even the host operator is out of scope.

Verifiable identity

Each session receives a short-lived, SPIFFE-style signed identity bound to its agent, tier and namespace. Confidential-tier identities are released only after attestation.

Governed gateway

MCP and A2A calls pass through one policy point. ToolPolicy rules allow, deny, rate-limit or require human approval — per agent, per tool, per argument.

Audit ledger

Every decision is written as a hash-chained record — session, identity, tool, argument digest, policy, outcome — and can be shipped to WORM object storage you control.

Trust tiers

TierRuntimeRuntimeClassBoundaryTypical use
tier-0 gVisor (runsc)gvisor User-space kernel intercepts syscalls Code interpreters, data analysis, untrusted scripts
tier-1 Kata Containers + Firecrackerkata-fc Hardware-virtualised microVM per session Agents with build tools, browsers, broader syscall needs
tier-2 Kata CoCo (SEV-SNP / TDX)kata-qemu-snp Encrypted memory, remote attestation required Regulated data, customer secrets, untrusted infrastructure
Sovereignty

Sovereign by architecture, not by contract.

Sovereignty is three questions: whose law applies, who can operate it, and who can technically reach the data. MAQPNA is built so the answer to all three can be you.

Whose law applies?

Jurisdictional

  • Runs entirely on your clusters, in your chosen country or region
  • A cluster-wide SovereigntyPolicy pins jurisdiction, registries and egress
  • Every audit record carries the declared jurisdiction
Who can operate it?

Operational

  • Open source under Apache-2.0 — no vendor control plane
  • Zero phone-home: no telemetry, licence checks or update calls
  • Signed, offline air-gap bundle for disconnected installs
Who can reach the data?

Technical

  • Confidential VMs keep session memory encrypted from the host
  • Secrets and identities released only to attested workloads
  • Signing keys held by you — file, PKCS#11 HSM or KMS

Attestation-gated secrets

An init agent collects SEV-SNP or TDX evidence; the attestation service checks it against your reference values (or a Trustee KBS) before any identity is minted.

Customer-held keys

The identity broker signs with keys you provision. Rotate them on your schedule; MAQPNA never generates production keys for you.

Zero phone-home

MAQPNA makes no outbound calls by default. The only egress is what you configure — and that is constrained by an allowlist.

Air-gap bundle

Images, Helm chart, upstream manifests, SBOMs and checksums in one signed tarball, installable into a private registry with no internet access.

Immutable evidence

Ship the audit ledger to in-country S3-compatible storage with Object Lock (e.g. MinIO) for write-once retention.

EU AI Act & CRA evidence

Logs, policies, SBOMs and signed provenance that help you document oversight, traceability and supply-chain controls for your own conformity work.

Honest scope: MAQPNA gives you the technical controls and the evidence. Regulatory compliance depends on how you deploy and operate it — we don't claim certifications we don't have. Read the sovereignty guide →

Who it's for

For the people who have to say yes to agents in production.

Platform teams

Offer "agents as a service" on the Kubernetes you already run. CRDs, Helm, GitOps — no new control plane, no per-team sandbox snowflakes.

  • Upstream agent-sandbox under the hood
  • Warm pools for fast session start
  • One gateway for every MCP server

Security & compliance

Get a real isolation boundary, a policy point you can review, and an audit trail you can hand to an auditor.

  • Default-deny egress per session
  • Human approval for high-risk tools
  • Tamper-evident decision log

Regulated EU enterprises

Banks, insurers, healthcare and public sector teams that need agents without handing data or control to a foreign cloud.

  • Runs on-prem or on sovereign clouds
  • Confidential computing for sensitive data
  • Fully disconnected operation

Built on open standards and upstream projects

  • kubernetes-sigs/agent-sandbox
  • gVisor
  • Kata Containers
  • Firecracker
  • Confidential Containers
  • SPIFFE-style identity
  • Model Context Protocol
  • Agent2Agent (A2A)
  • Sigstore cosign
Editions

Open core. Free to run, supported when it matters.

The runtime is open source. Commercial editions add support, hardened distributions and sovereign operations — never a hosted dependency.

Community

Free

Apache-2.0. For teams evaluating or running agents on their own.

  • Operator, gateway, identity broker, CLI
  • All three trust tiers
  • ToolPolicy and audit ledger
  • Helm chart and kind quickstart
  • Community support on GitHub
Get started on GitHub

Sovereign Edition

Contact us

For regulated and public-sector deployments with strict jurisdictional requirements.

  • Everything in Enterprise
  • Air-gapped delivery and offline updates
  • Confidential-computing reference architectures
  • HSM / KMS key-custody integrations
  • Support from within the EU
Talk to us
Get started

Run your first sandboxed agent in minutes.

Spin up a local kind cluster with gVisor, install MAQPNA with Helm and watch a governed tool call land in the audit ledger.

terminal
# requires docker, kind, kubectl, helm
git clone https://github.com/maqpna/maqpna && cd maqpna
make quickstart   # kind + gVisor + agent-sandbox + MAQPNA
make demo

Early access is by email — write to hello@maqpna.com. We don't use tracking or newsletter tools on this site.