Hermes Atlas
Deployment & hosting · works with Hermes Agent

kars

Azure/kars

Reference stack for running AI agents, including Hermes, in hardened per-agent Kubernetes sandboxes

In short

kars is an open-source Agent Reference Stack for Kubernetes from the Azure Cloud Native team, built to run AI agents such as Hermes Agent in hardened per-agent sandboxes. A Rust router brokers every external call, so the agent itself holds no credentials.

What kars does

kars gives each agent its own sandbox pod. The agent process runs under a different UID than a Rust inference router, which holds the credentials and brokers every external call, enforcing identity, content safety, token budgets, rate limits, tool policy and a tamper-evident audit chain. An init step adds an iptables egress guard so the agent can only reach the router locally. The README frames this as limiting the blast radius of a prompt-injected agent.

kars is multi-runtime. Agents on different frameworks exchange messages over AgentMesh, which uses the Signal Protocol so the relay sees only ciphertext. The OpenClaw to Hermes path is exercised end to end on every push, while other adapters are still being brought to the same bar. The command kars dev --target local-k8s runs an agent on a local kind cluster with the same Helm chart, NetworkPolicies and sidecars as production AKS, and a Headlamp plugin shows sandboxes, policy CRDs and trust topology.

Key features

  • One hardened sandbox pod per agent, with no credentials inside the agent
  • Rust inference router enforcing identity, content safety, budgets, tool policy and audit
  • End-to-end encrypted AgentMesh messaging between agents on different frameworks
  • OpenClaw to Hermes messaging tested end to end on every push
  • Local kind dev loop that mirrors AKS
  • Headlamp plugin for sandboxes, policy CRDs and trust topology

When to use it

  • Running a Hermes agent on AKS with limited blast radius
  • Letting Hermes and OpenClaw agents message each other over an encrypted mesh
  • Trying a governed agent locally on kind before deploying to a cluster

Who it is for: Platform and security engineers who want to run agents such as Hermes on Kubernetes with strict credential and network controls.

How it fits with Hermes Agent

Supports Hermes Agent as one of several agent runtimes, with Hermes to OpenClaw messaging over the mesh tested on every push.

How to install kars

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

npm i -g @kars-runtime/cli
kars dev --release --target local-k8s
kars connect dev-agent

Requirements: Node.js 22+ for the CLI; the quickstart runs on a local Kubernetes (kind) cluster

Note: The README states that kars is a reference implementation and not an officially supported Microsoft product.

FAQ

What is kars?

kars is an open-source Agent Reference Stack for Kubernetes. It runs each AI agent in a hardened sandbox, routes every external call through a governed Rust router and connects agents over an encrypted mesh.

Does kars work with Hermes Agent?

Yes. Hermes is supported as one of several agent runtimes, and messaging between OpenClaw and Hermes over the mesh is tested end to end on every push.

Is kars an official Microsoft product?

No. The README says kars is not an officially supported Microsoft product but an open-source reference implementation from the Azure Cloud Native team. It is released under the MIT license.

Similar deployment for Hermes Agent

All deployment

Related guides: How to run Hermes Agent securely · How to install Hermes Agent · Connect Hermes agents on several machines with Hermes Desktop