MAQPNADocs

Solution architecture overview#

MAQPNA has a control plane that turns declarative resources into running, identity-bound, network-fenced sandboxes, and a data plane that governs every call those sandboxes make. Both run in your cluster, in your jurisdiction, with your keys. Nothing calls out to MAQPNA the vendor.

MAQPNA solution architecture: the control plane (Kubernetes API, operator, agent-sandbox controller, identity broker, attestation service) creates one sandbox per session at tier-0, tier-1 or tier-2; every call from a sandbox goes through the gateway to MCP servers, model endpoints, other agents or the web; the gateway keeps shared state in PostgreSQL and ships the audit ledger to SIEM and write-once storage

The same picture as a diagram#

flowchart LR
    subgraph People["People and clients"]
      GIT["Platform team<br/>GitOps, kubectl, maqpna apply"]
      DEV["Developers<br/>maqpna CLI, SDKs"]
      APR["Approvers and auditors<br/>console, MAQPNA Desk, chat"]
    end
    subgraph Cluster["Your Kubernetes cluster"]
      subgraph CP["Control plane"]
        KAPI["Kubernetes API<br/>maqpna.com CRDs"]
        OP["maqpna-operator"]
        AS["agent-sandbox controller"]
        IB["maqpna-identity<br/>:8081, bootstrap :8083"]
        AT["maqpna-attest :8082"]
      end
      subgraph NS["Agent namespaces, default-deny"]
        T0["Sandbox tier-0<br/>gVisor"]
        T1["Sandbox tier-1<br/>Kata + Firecracker"]
        T2["Sandbox tier-2<br/>confidential VM"]
      end
      subgraph DP["Data plane"]
        GW["maqpna-gateway<br/>N replicas :8080"]
        PG[("PostgreSQL<br/>shared state, optional")]
      end
    end
    subgraph Up["Your upstreams"]
      MCP["MCP servers"]
      LLM["Model endpoints"]
      A2A["Other agents"]
      WEB["The web"]
    end
    subgraph Ev["Evidence and operations"]
      SIEM["SIEM"]
      WORM[("WORM storage")]
      OTEL["OpenTelemetry"]
      PROM["Prometheus"]
    end
    IDP["Your identity provider<br/>OIDC, CIBA"]
    TR["Your Trustee verifier"]

    GIT --> KAPI
    DEV --> KAPI
    DEV --> GW
    APR --> GW
    KAPI --> OP
    OP --> AS
    OP -- "mint" --> IB
    OP -- "register release" --> AT
    OP -- "rendered ConfigMaps" --> GW
    AS --> T0 & T1 & T2
    IB -- "session token" --> T0
    IB -- "bootstrap" --> T1
    AT -- "sealed token" --> T2
    AT --> TR
    T0 & T1 & T2 -- "MCP, A2A, model, egress" --> GW
    GW --> MCP & LLM & A2A & WEB
    GW <--> PG
    GW --> IDP
    GW --> SIEM & WORM & OTEL
    PROM -. scrape .-> GW

Control plane#

Component Responsibility Deep dive
Kubernetes API and CRDs Thirteen kinds in maqpna.com/v1alpha1: Agent, AgentSession, AgentSessionSnapshot, TrustTier, ToolPolicy, MCPServer, A2APeer, AgentRevocation, BudgetPolicy, SovereigntyPolicy, Tenant, MemoryStore, ConnectedAccount CRD data model
Operator (maqpna-operator) Reconciles sessions into sandboxes, tokens and NetworkPolicies; renders policies, the MCP server registry, model routes, A2A routes, revocations, budgets, memory stores and tenants into ConfigMaps for the gateway; keeps warm pools; reports sandbox usage and counts billable nodes Operator
agent-sandbox (upstream) Runs the Sandbox, SandboxClaim and SandboxWarmPool objects the operator creates Session lifecycle
Identity broker (maqpna-identity) Mints Ed25519 session tokens, publishes JWKS, exchanges and delegates tokens, bootstraps warm-pool pods Identity broker
Attestation service (maqpna-attest) Releases a token to a tier-2 sandbox only after hardware attestation, sealed to a key inside the VM Attestation

Data plane#

Component Responsibility Deep dive
Sandboxes One per session, at a trust tier; default-deny network; no Kubernetes credentials Agents, sessions, sandboxes
Gateway (maqpna-gateway) Every MCP (/mcp), A2A (/a2a), model (/llm) and browser egress call: identity, kill switch, DLP, guards, tool pins, policy, taint, budgets, approvals, residency dialer, credentials, metering and the audit ledger. Also the admin API (/v1/*) Gateway, gateway pipeline
State backend file (default, per replica) or PostgreSQL (shared by every gateway and attestation replica) State backend

Clients#

Client What it does Deep dive
CLI (maqpna) and maqpna-install Local MAQPNA, manifests, sessions, approvals, kill switch, audit, install and upgrade CLI and plugin
Console and MAQPNA Desk Web UI (served by maqpna console) and the desktop approvals inbox Console and Desk
SDKs Python, TypeScript and Go libraries: tool and model calls through the gateway, approvals, result reporting, warm-pool bootstrap Developer loop

One session, end to end#

  1. A platform engineer applies a TrustTier, an Agent, a ToolPolicy and its MCPServers. The operator validates them against the default sovereignty policy and renders the policies and registry into ConfigMaps the gateway hot-reloads.
  2. Someone (a person, a portal or maqpna session start) creates an AgentSession for a user.
  3. The operator checks the agent, tier, principal, sovereignty, scopes, TTL, revocations and quotas, then asks the identity broker for a session token (or registers an attestation release for tier-2), and creates the sandbox and its NetworkPolicy.
  4. The agent starts with MAQPNA_GATEWAY_URL, MAQPNA_TOOL_<NAME>_URL and MAQPNA_MODEL_ENDPOINT pointing at the gateway, and the token at /var/run/maqpna/token.
  5. Each tool call goes to the gateway, which verifies the token, checks the kill switch, scans with DLP, evaluates policy with the session's taint, checks budgets, holds the call for approval when a rule says so, forwards it with its own upstream credential, scans the result and appends an audit record.
  6. Approvers see held calls in the console, MAQPNA Desk, the CLI or chat; the user may confirm on their own device (CIBA).
  7. The session ends (result reported, TTL reached, revoked or deleted). The operator records the outcome, deletes the sandbox and token, and reports the sandbox time to the gateway for metering.
  8. Auditors verify the ledger with maqpna audit verify and export evidence; one elected gateway replica ships the ledger to your SIEM and write-once storage.

Design principles visible in the code#

  • Built on upstream. Sandboxes come from kubernetes-sigs/agent-sandbox (driven unstructured, so MAQPNA is not tied to one release); isolation from gVisor, Kata Containers, Firecracker and Confidential Containers; protocols are MCP, A2A, SPIFFE, OIDC, OpenAI-compatible model APIs.
  • One enforcement point. Sandboxes can only reach DNS and the gateway, so every call gets a decision.
  • Standard library on the request path. The gateway's governance path (policy, DLP, identity, ledger, OIDC, OpenTelemetry) is Go standard library only; Cedar and the PostgreSQL driver are opt-in.
  • Fail-safe defaults. No applicable policy, an unreadable revocation list or an unknown DLP profile means deny.
  • Evidence over convenience. Arguments are hashed, not stored; checkpoints are signed with your key.
  • Licence never blocks traffic.

What you see#

maqpna status gives a one-screen status of an installation: the Helm release (REVISION STATUS CHART APP UPDATED DESCRIPTION), the workloads (WORKLOAD COMPONENT READY IMAGE), sessions, pending approvals and the audit ledger. maqpna version prints every component's version with the skew check. See maqpna status and maqpna version.