Helm, Kubernetes and EKS
The openagentix chart (0.2.1) installs a complete stack with one command (bundled PostgreSQL and Valkey, generated credentials, demo and air-gapped modes). The chart lives in
open-agentix/open-agentix-helm.
Value names may still change before 1.0; the chart’s values.yaml is authoritative.
What the chart deploys
Section titled “What the chart deploys”- api (control node), worker and ui deployments;
- PostgreSQL as an optional bundled dependency, or an external database;
- a migrations Job as a Helm hook;
- NetworkPolicies with default deny and explicit egress;
- PodSecurity
restricted(non-root, read-only root file system, no privilege escalation); - HorizontalPodAutoscaler, PodDisruptionBudget and a
ServiceMonitorfor the Prometheus Operator; - ingress for nginx or the AWS Load Balancer Controller (ALB).
Install
Section titled “Install”kubectl create namespace openagentixkubectl -n openagentix create secret generic openagentix-secrets \ --from-literal=database-url='postgres://…' \ --from-file=audit-signing-key=./audit-ed25519.pemhelm install openagentix ./charts/openagentix -n openagentix -f values.yamlPublishing the chart as a Helm repository and as an OCI artifact is on the roadmap.
Values (illustrative)
Section titled “Values (illustrative)”database: external: true existingSecret: openagentix-secrets
auth: oidc: issuer: https://login.example.com/realms/main clientId: openagentix existingSecret: openagentix-oidc
ingress: className: alb # or nginx host: agents.example.com
networkPolicy: enabled: true # default deny egress: - to: bedrock-vpc-endpoint cidr: 10.0.12.0/24 ports: [443]
serviceAccount: annotations: eks.amazonaws.com/role-arn: arn:aws:iam::123456789012:role/openagentix-bedrockEKS and Bedrock
Section titled “EKS and Bedrock”- Create an IAM role for IRSA that trusts your cluster’s OIDC provider and the chart’s service
account, with
bedrock:InvokeModelon the allowed models. - Annotate the service account with the role ARN (see above).
- Create a Bedrock VPC interface endpoint or set a proxy, and allow it in the network policy.
- Configure the Bedrock provider without any static keys.
From 0.2, the kubernetes-job runner starts one Job per run in the
openagentix-runs namespace with its own service account (openagentix-worker), IRSA annotation
and NetworkPolicy.