k8s-viper
Dockerized k3s on Viper. Isolated gVisor SandboxAgents on Agent Substrate — not plain Agents. They sit idle until a chat, then a worker comes up.
SandboxAgents on this node. Actors sit idle until a chat, then a gVisor worker comes up. The idle/active flip is an illustration of that lifecycle, not live pod status.
Kubernetes helper for this dockerized k3s lab.
Home FortiGate 80F assistant (fw-maniak-hq).
Executive AWS budget and capacity for us-east-2.
Manager-facing IT tickets on a personal developer instance.
Executive GCP budget and capacity for us-east1.
F5 BIG-IP VIP monitor for 172.16.10.10.
Read-only Arista cEOS operator for the Containerlab spine/leaf demo.
- chat
- kagent
- SandboxAgent
- gVisor actor
- MCP
- target
SandboxAgents
Same inventory as the cluster above. Detail, live shots, and vault path names live on /agents/. The lab map is in the handbook.
Kubernetes helper for this dockerized k3s lab.
Home FortiGate 80F assistant (fw-maniak-hq).
Executive AWS budget and capacity for us-east-2.
Manager-facing IT tickets on a personal developer instance.
Executive GCP budget and capacity for us-east1.
F5 BIG-IP VIP monitor for 172.16.10.10.
Read-only Arista cEOS operator for the Containerlab spine/leaf demo.
How it works
Imperative install only for k3s + Argo + root app. Platform services are GitOps. LAN consoles stay off this public site.
bootstrap.sh → dockerized k3s (k3s-viper) + Argo CD + root Application
argocd/apps/* (GitOps, auto-sync)
Traefik · Vault · ESO · Headlamp · agentgateway · Langfuse · Substrate · kagent
kagent UI :30500 (LAN-only) → gpt-5.5 via agentgateway :30100
Agent Substrate (ate-system) → gVisor workers (kagent-default)ExternalSecret paths only.Pins
Official pairing. Do not bump these to “fix” a Ready=False agent.
| Piece | Pin |
|---|---|
| kagent OSS | 0.10.0-rc2 |
| Agent Substrate | 0.0.9 |
| WorkerPool | kagent-default |
| kagent UI | :30500 |
| model | gpt-5.5 via agentgateway :30100 |