MAQPNADocs

What MAQPNA is#

MAQPNA is the sovereign runtime for AI agents. It runs AI agents on your own Kubernetes cluster, or on your laptop, and puts every tool call, model call and egress connection through one gateway. The gateway checks identity, policy, data-loss rules and budgets, asks a human when a rule says so, and writes a tamper-evident audit ledger. Each session runs in an isolated sandbox with a short-lived identity. There is no vendor control plane and no phone-home.

MAQPNA starts from one assumption: the model will sometimes be wrong or manipulated, so safety must not depend on the model. Every action an agent takes crosses a runtime that can check it, stop it, ask about it and prove afterwards what happened.

The four things every session gets#

When you run an agent under MAQPNA, each run (a session) gets four things:

  1. Its own sandbox. A gVisor container (tier-0), a Kata Containers + Firecracker microVM (tier-1) or a confidential VM with hardware attestation (tier-2). The sandbox runs non-root, with a read-only root filesystem, no Kubernetes service-account token and a default-deny NetworkPolicy whose only exit is the gateway.
  2. A short-lived, signed identity. The identity broker issues an Ed25519-signed token whose subject is a SPIFFE-style ID (spiffe://<trust-domain>/ns/<ns>/agent/<agent>/session/<session>) and whose act claim names the person the agent acts for. The token carries scopes such as tools:github and expires within minutes.
  3. A governed gateway. Every Model Context Protocol (MCP) tool call, agent-to-agent (A2A) call, model call and browser egress connection goes through the MAQPNA gateway. The gateway verifies the token, checks the kill switch, runs data loss prevention (DLP), evaluates policy, applies taint and budgets, and holds the call for approval when a rule requires it.
  4. A tamper-evident audit ledger. Every decision is appended to a SHA-256 hash chain with signed checkpoints. maqpna audit verify proves that no record was changed, removed or reordered.
flowchart LR
    U([Person the agent acts for]) -. on behalf of .-> S
    subgraph SB["Sandbox (one per session)"]
      S["Agent process<br/>+ session token"]
    end
    S -- "MCP, A2A, model and egress calls" --> G["MAQPNA gateway<br/>identity · policy · DLP · taint<br/>budgets · approvals · audit"]
    G -- allowed --> T["MCP servers<br/>other agents<br/>model endpoints"]
    G -- "held for approval" --> H([Approver or the user])
    G -- every decision --> L[("Audit ledger<br/>hash chain + checkpoints")]
    IB["Identity broker"] -- "short-lived token" --> S

What MAQPNA is made of#

Part What it does Code
Operator (maqpna-operator) Turns Agent and AgentSession resources into sandboxes (through the upstream agent-sandbox project), tokens and NetworkPolicies, and renders policies and registries for the gateway internal/controller, cmd/maqpna-operator
Gateway (maqpna-gateway) Governs every MCP, A2A, model and egress call; holds approvals; writes the ledger cmd/maqpna-gateway
Identity broker (maqpna-identity) Issues session tokens, publishes its public keys (JWKS), exchanges and delegates tokens, bootstraps warm-pool pods cmd/maqpna-identity
Attestation service (maqpna-attest) Releases tokens to tier-2 confidential VMs only after hardware attestation cmd/maqpna-attest, cmd/maqpna-attest-agent
CLI (maqpna) and its lifecycle plugin (maqpna-install) Runs a local MAQPNA, applies manifests, approves calls, verifies the ledger, installs and upgrades cmd/maqpna, cmd/maqpna-install
Console and MAQPNA Desk The web UI and the desktop approvals inbox console/, desktop/
SDKs Python, TypeScript and Go libraries agents use to call tools through the gateway sdk/

Read the solution architecture overview for how these parts connect.

What MAQPNA is not#

  • Not an agent framework. MAQPNA hosts agents built with LangGraph, CrewAI, the OpenAI Agents SDK, the Claude Agent SDK or your own code. It does not replace them. See How MAQPNA compares.
  • Not a model. Model serving is yours (vLLM, KServe or a hosted API reached through an allow-listed route).
  • Not a SaaS. You install and run it. Nothing at runtime calls MAQPNA the vendor; see What "sovereign" means.
  • Not a fix for the model itself. MAQPNA limits and records what a fooled model can do; it cannot stop the model being fooled. The security model lists what is out of scope.

What you see#

A local MAQPNA starts in one command, without a cluster:

$ maqpna dev up
local MAQPNA is up (/home/you/my-agent/.maqpna)
  gateway   http://127.0.0.1:8080
  broker    http://127.0.0.1:8081
  mcp       echo -> http://127.0.0.1:8090/mcp
next: maqpna dev run -- <your agent command>

Your agent then runs under its own session identity (maqpna dev run -- python agent.py), and maqpna dev timeline --last lists each tool call it made and the decision on it. The developer loop walks through it step by step.

Next steps#

  1. Read the core concepts, starting with agents, sessions and sandboxes.
  2. Follow one call end to end in a governed tool call.
  3. Look up a command in the reference, for example maqpna dev up.