An agent’s real instructions are assembled at runtime from model output, tool results, retrieved documents, and MCP servers, none of which you fully control. So the safe assumption is that an agent is untrusted code that runs attacker-influenced instructions.

KARS takes that assumption seriously. It is an open-source, Kubernetes-native runtime for AI agents on Azure: one sandbox per agent, per-pod kernel isolation, zero credentials in the agent process, and an end-to-end encrypted mesh between agents.

KARS dev first run

The part I find clever is the governance model. You declare an agent’s model, tools, memory, and MCP access as Kubernetes CRDs, and a per-pod router enforces them identically across every framework: MAF, LangGraph, and the rest. Team A on one harness and Team B on another share one governance surface and one audit trail. Governing agents at scale becomes a Kubernetes problem, not an N-frameworks problem.

It builds on the hardened Azure Linux substrate Brendan Burns described last month.

Read the announcement

Thanks for reading! :-)