MAQPNA has a control plane that turns declarative resources into running, identity-bound, network-fenced sandboxes, and a data plane that governs every call those sandboxes make. Both run in your cluster, in your jurisdiction, with your keys. Nothing calls out to MAQPNA the vendor.
Reconciles sessions into sandboxes, tokens and NetworkPolicies; renders policies, the MCP server registry, model routes, A2A routes, revocations, budgets, memory stores and tenants into ConfigMaps for the gateway; keeps warm pools; reports sandbox usage and counts billable nodes
Every MCP (/mcp), A2A (/a2a), model (/llm) and browser egress call: identity, kill switch, DLP, guards, tool pins, policy, taint, budgets, approvals, residency dialer, credentials, metering and the audit ledger. Also the admin API (/v1/*)
A platform engineer applies a TrustTier, an Agent, a ToolPolicy and its MCPServers. The operator validates them against the default sovereignty policy and renders the policies and registry into ConfigMaps the gateway hot-reloads.
Someone (a person, a portal or maqpna session start) creates an AgentSession for a user.
The operator checks the agent, tier, principal, sovereignty, scopes, TTL, revocations and quotas, then asks the identity broker for a session token (or registers an attestation release for tier-2), and creates the sandbox and its NetworkPolicy.
The agent starts with MAQPNA_GATEWAY_URL, MAQPNA_TOOL_<NAME>_URL and MAQPNA_MODEL_ENDPOINT pointing at the gateway, and the token at /var/run/maqpna/token.
Each tool call goes to the gateway, which verifies the token, checks the kill switch, scans with DLP, evaluates policy with the session's taint, checks budgets, holds the call for approval when a rule says so, forwards it with its own upstream credential, scans the result and appends an audit record.
Approvers see held calls in the console, MAQPNA Desk, the CLI or chat; the user may confirm on their own device (CIBA).
The session ends (result reported, TTL reached, revoked or deleted). The operator records the outcome, deletes the sandbox and token, and reports the sandbox time to the gateway for metering.
Auditors verify the ledger with maqpna audit verify and export evidence; one elected gateway replica ships the ledger to your SIEM and write-once storage.
Built on upstream. Sandboxes come from kubernetes-sigs/agent-sandbox (driven unstructured, so MAQPNA is not tied to one release); isolation from gVisor, Kata Containers, Firecracker and Confidential Containers; protocols are MCP, A2A, SPIFFE, OIDC, OpenAI-compatible model APIs.
One enforcement point. Sandboxes can only reach DNS and the gateway, so every call gets a decision.
Standard library on the request path. The gateway's governance path (policy, DLP, identity, ledger, OIDC, OpenTelemetry) is Go standard library only; Cedar and the PostgreSQL driver are opt-in.
Fail-safe defaults. No applicable policy, an unreadable revocation list or an unknown DLP profile means deny.
Evidence over convenience. Arguments are hashed, not stored; checkpoints are signed with your key.
maqpna status gives a one-screen status of an installation: the Helm release (REVISION STATUS CHART APP UPDATED DESCRIPTION), the workloads (WORKLOAD COMPONENT READY IMAGE), sessions, pending approvals and the audit ledger. maqpna version prints every component's version with the skew check. See maqpna status and maqpna version.