Everything in ctxmesh is a Kubernetes custom resource in the agents.ctxmesh.ai API group,
served at v1beta1 (the GA API posture — see Versioning). You compose an agent
and its governance by authoring these resources and referencing policies from the
AgentDeployment spec. A missing or invalid reference fails closed — the agent is held, not
served ungoverned.
A policy is authored once and reused. An agent opts in by reference:
apiVersion:agents.ctxmesh.ai/v1beta1
kind:AgentDeployment
metadata:
name:support-agent
namespace:my-team
spec:
image:ghcr.io/my-org/support-agent:1.0.0
# The model is chosen in the agent's code by calling the injected gateway
# (MODEL_GATEWAY_URL) with model="<ModelRoute name>" — there is no modelRouteRef.
guardrailPolicyRef:default-guardrails
approvalPolicyRef:sensitive-tools
feedbackStoreRef:support-feedback
evalSuiteRef:support-quality
A dangling reference sets Ready=False on the agent and holds it (no serving revision) — the
control plane is fail-closed, so an agent is never served without the governance it names.