Skip to content

Networking and isolation ​

OpenCrane keeps the public API, trusted services and untrusted runtime Jobs on separate network surfaces. Every runtime connection is outbound and every namespace starts deny-by-default.

See also: Hosting and deployment (namespace layout), Organisation boundary (silo scope), and Identity and network isolation (identity-keyed policy).

Traffic shape ​

text
browser
  │ HTTPS + OIDC session
  ▼
Ingress ──► OpenCrane public API

runtime Job
  │ projected identity + one-use bootstrap + outbound stream
  ▼
OpenCrane internal runtime API
  │
  ├──► model routing
  ├──► governed tool custody
  └──► memory and artifact services

There is no public route, Service or Ingress for an individual runtime Job. A Job also has no Kubernetes RBAC, provider credential or unrestricted east-west access.

Namespace policy ​

Namespace classIngressEgress
Trusted serverpublic traffic through Ingress; explicit same-silo service callersdatabase, same-silo services and declared external dependencies
Personal runtimenoneDNS, same-silo OpenCrane and LiteLLM only
Managed runtimenoneDNS and explicitly declared same-silo agent services
Worker namespacesnoneonly the exact broker or service required by that job class

The chart also applies aggregate Job, Pod, CPU and memory quotas. Admission rejects sidecars, host access, privileged containers, durable mounts, unpinned images and arbitrary Secret projections.

Runtime authentication ​

Network reachability is not authority. OpenCrane separately verifies the projected token audience, namespace, ServiceAccount, Job UID, first-Pod UID, run, attempt and agent revision. A one-use bootstrap binds the runtime's proof key before the command stream is admitted.

TIP

Treat NetworkPolicy as the portable L3/L4 floor and workload proof as the application boundary. Both must pass.

Operator checks ​

  1. Confirm the CNI enforces NetworkPolicy.
  2. Confirm the trusted, personal-runtime and managed-runtime namespaces are distinct.
  3. Render the chart and inspect the runtime admission policies and quotas.
  4. Verify runtime Jobs have no Service, Ingress, role binding or persistent volume.
  5. Verify only the ingress controller can reach the public API port.

Source: apps/opencrane/helm/templates/_networkpolicy.tpl and libs/backend/agents/runtime/k8s-launcher.

Released under the AGPL-3.0-or-later License.