@berthos/adapter-k8s
v0.2.4
Published
DeployAdapter implementation targeting a Kubernetes cluster
Downloads
664
Maintainers
Readme
@berthos/adapter-k8s
Deploy a Berth sandbox to your own Kubernetes cluster, one Pod per instance, with berth deploy --fleet=k8s.
Berth runs an AI agent's tools in a sandbox. Each tool declares what it may touch in a berth.yml manifest, and the Linux kernel enforces it.
Install it, with the Kubernetes client, next to @berthos/cli (add -g if the CLI is global):
npm install @berthos/adapter-k8s @kubernetes/client-nodeUsage
From the app's directory:
berth deploy --fleet=k8s
berth deploy --fleet=k8s --count=3 --region=us-east-1
berth fleet status k8sThe adapter uses your default kubeconfig (KUBECONFIG or ~/.kube/config) and deploys to BERTH_K8S_NAMESPACE (default default). --region becomes a topology.kubernetes.io/region node selector.
Limits
- It doesn't push the image. Push it to a registry the cluster can pull from (or
kind load docker-imagefor kind). - The Pod needs
SYS_ADMIN, which Pod Security Admission'srestrictedlevel rejects. - Capabilities are enforced only if the node's kernel has Landlock (Linux 6.7+).
envvalues from a~/.berthrcalias appear in the Pod spec, not in a KubernetesSecret.
