MAQPNADocs

maqpna-operator

The Kubernetes operator: reconciles agents, sessions, trust tiers and policies.

Server binaries

Synopsis#

maqpna-operator [flags]

Flags#

FlagTypeDescriptionDefault
-attest-agent-imagestringAttest-agent image (init container that redeems attested releases + renewer sidecar).<release-registry>/maqpna-attest-agent:latest
-attest-response-pubkey-filestringPEM Ed25519 public key of maqpna-attest's -response-signing-key; injected into attest-agent containers so they reject unsigned or forged attest responses.none
-attest-tsm-host-pathstringIf set, hostPath mounted at /sys/kernel/config/tsm into the attest-agent containers (configfs-tsm).none
-attest-urlstringAttestation service base URL (POST /v1/releases).http://maqpna-attest.maqpna-system.svc:8082
-bootstrap-audiencestringAudience warm-pool SandboxTemplates must project their ServiceAccount token for (identity broker /v1/bootstrap).maqpna-bootstrap
-bootstrap-portintIdentity broker bootstrap port (SandboxClaim-mode NetworkPolicy egress).8083
-broker-urlstringIdentity broker base URL (POST /v1/token).http://maqpna-identity.maqpna-system.svc:8081
-browser-imagestringImage of the browser profile sidecars (Chromium + maqpna-egress-relay).<release-registry>/maqpna-browser:latest
-code-interpreter-imagestringImage of the codeInterpreter profile exec sidecar (maqpna-exec).<release-registry>/maqpna-code-interpreter:latest
-default-session-ttldurationSession TTL when neither the session nor any cap sets one.1h0m0s
-gateway-namespacestringNamespace of gateway/attest pods and the policies/models ConfigMaps.maqpna-system
-gateway-urlstringGateway URL injected into sandboxes.http://maqpna-gateway.maqpna-system.svc:8080
-health-probe-bind-addressstringAddress the health probe endpoint binds to.:8081
-kube-api-burstintClient-side burst towards the API server.100
-kube-api-qpsfloatClient-side QPS limit towards the API server.50
-kubeconfigstringPaths to a kubeconfig. Only required if out-of-cluster.none
-leader-electswitchEnable leader election for the controller manager.none
-license-filestringInstalled MAQPNA licence (Secret of Helm license.secretRef, mounted optional); missing = Community. Only switches paid features on, never affects sessions.none
-mcpserver-shared-namespacesstringComma-separated namespaces whose MCPServers may set shared: true (empty = any namespace).none
-metrics-bind-addressstringAddress the metrics endpoint binds to (0 disables).:8080
-model-credentials-dirstringGateway mount path of Secret maqpna-model-credentials; models.json apiKeyFile paths point into it./var/run/maqpna-model-credentials
-node-count-intervaldurationHow often billable nodes (nodes running agent sandbox pods) are sampled into ConfigMap maqpna-usage-nodes; 0 disables.1m0s
-principal-bindingstringPrincipal-binding admission mode installed with the chart (off|requester|trustedCreators); recorded in status.principal.verifiedBy and the maqpna_principal_verified claim.off
-sandbox-api-versionstringagent-sandbox API version (v1beta1 for agent-sandbox >= v1.0, v1alpha1 for <= v0.5).v1beta1
-sandbox-snapshot-apistringUpstream pod-snapshot API <group>/<version> for the SandboxSnapshot strategy (e.g. podsnapshot.gke.io/v1); empty = VolumeSnapshot only.none
-session-workersintAgentSessions reconciled in parallel (quota admission stays serialized).8
-spire-trust-domainstringFallback SPIFFE trust domain of sandbox SVIDs (the identity broker's --trust-domain) for sessions whose SPIFFE ID is not minted yet (attestation-gated); the minted SPIFFE ID (token subject, tenant trust domain under F-27) always wins.none
-spire-workload-registrationswitchLabel and annotate sandbox pods (maqpna.com/spiffe, maqpna.com/spiffe-id) for a SPIRE ClusterSPIFFEID.none
-tenant-trust-domain-suffixstringDefault Tenant trust domain is <tenant>.<suffix>.maqpna.local
-token-ttldurationMaximum lifetime of minted session tokens (refreshed at 80%).15m0s
-upstream-credential-resyncdurationHow often MCPServer credential Secrets and Agent model apiKeySecretRef Secrets are re-read to pick up rotation.1m0s
-usage-report-token-filestringProjected ServiceAccount token (gateway sandboxUsage.audience) presented with usage reports./var/run/secrets/maqpna/usage/token
-usage-report-urlstringGateway endpoint for finished sessions' sandbox time (e.g. http://maqpna-gateway.maqpna-system.svc:8080/v1/usage/sandbox); empty disables reporting.none
-user-oidc-audiencestringRequired audience (client id) of user ID tokens.none
-user-oidc-groups-claimstringClaim holding the user's groups.groups
-user-oidc-issuerstringOIDC issuer for AgentSession spec.userAssertionRef ID tokens (empty disables userAssertionRef).none
-user-oidc-jwksstringJWKS URL of the user OIDC issuer (default: discovery).none
-user-oidc-username-claimstringClaim compared with spec.user (default: email, preferred_username or sub).none
-warmpool-namespacestringDefault namespace for tier SandboxWarmPools.default
-watch-sandboxesswitchWatch upstream Sandbox/SandboxClaim/SandboxWarmPool objects (requires agent-sandbox CRDs installed).true
-workspace-sizestringDefault size of the codeInterpreter session workspace PVC.1Gi
-zap-develswitchDevelopment Mode defaults(encoder=consoleEncoder,logLevel=Debug,stackTraceLevel=Warn). Production Mode defaults(encoder=jsonEncoder,logLevel=Info,stackTraceLevel=Error)none
-zap-encodervalueZap log encoding (one of 'json' or 'console')none
-zap-log-levelvalueZap Level to configure the verbosity of logging. Can be one of 'debug', 'info', 'error', 'panic' or any integer value > 0 which corresponds to custom debug levels of increasing verbositynone
-zap-stacktrace-levelvalueZap Level at and above which stacktraces are captured (one of 'info', 'error', 'panic').none
-zap-time-encodingvalueZap time encoding (one of 'epoch', 'millis', 'nano', 'iso8601', 'rfc3339' or 'rfc3339nano'). Defaults to 'epoch'.none

What happens when you run it#

  • A long-running server. The Helm chart starts it with these flags; set them through the chart's values rather than by hand.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed

Terminal demo#

maqpna-operator -h.cast