SYNKUBE

// agents

Agent platform on Kubernetes.

A reproducible template we run in production—spin up new agents for your org without long-lived secrets in the execution environment.

Talk to us about agents →

// architecture

KUBERNETESSLACKworkspace channelAGENT PODHermes gatewaychannels inAgent workerexecution + toolsGITHUB CREDENTIAL BROKERmint repo credentialsAGENT IDENTITYOIDC · cloud API tokensGITHUBgit repos · REST APICLOUD IAMAWS · GCP · AzureMCPexternal tool servers

// how it runs

Gateway, worker, trust services.

Channels hit the gateway. The worker runs your config and tools. For GitHub or cloud APIs it calls in-cluster Go services that mint short-lived credentials—nothing long-lived in the pod.

  1. Hermes gateway

    01
    • ▸Routes Slack, webhooks, and channels to the right worker
    • ▸Channel auth stays out of the execution pod
    • ▸One gateway can front many workers
  2. Agent worker

    02
    • ▸StatefulSet pod: context, KB, skills, and workspace you configure
    • ▸Model routing and MCP at runtime
    • ▸Calls broker and identity with Kubernetes service-account identity
  3. Trust services

    03
    • ▸GitHub credential broker: short-lived git and gh tokens
    • ▸Agent identity: OIDC for cloud provider APIs
    • ▸Signing keys and OAuth stay in trust services, not the worker

// trust boundary

What stays in the pod vs what does not.

AGENT WORKER PODyour setup + runtime stateContext, identity, rulesKnowledge base (read-only)Skills & workspace layoutMemory (preferences, corrections)Model config · MCP toolsTRUST SERVICESGitHub credential brokerApp credentials · OAuth · signing keysAgent identityOIDC mint · cloud API access

// pillars

What every production agent needs.

What you provide

Context

Identity, rules, scope

Knowledge base

Static reference docs

Skills

Callable procedures

Workspace

Repos, files, volume

How it runs

Tools

MCP, external APIs

Memory

Preferences, entities, corrections

Model

Provider, routing

Platform

Execution environment

Kubernetes pod, gateway

Trust & permissions

Broker, identity, policy

Channels

Slack, webhooks, gateway

Observability

Logs, metrics, traces

You supply the agent; durable work stays in your GitHub org.

You configure context, knowledge, skills, and workspace. The agent opens branches, commits, and PRs in repositories you own—state lives in your GitHub account, not in a disposable chat session.