LiteLLM & Langfuse Operators + WebSearch MCP now available

Enterprise AI governance
for Kubernetes

One Custom Resource deploys a complete AI platform — LLM gateway, observability, PII guardrails, policy engine, and MCP servers. Built for regulated industries.

palena-gateway.yaml
apiVersion: palena.ai/v1alpha1
kind: PalenaGateway
metadata:
  name: production
spec:
  gateway:
    litellm:
      replicas: 3
  observability:
    langfuse:
      enabled: true
  shield:
    enabled: true
    failMode: closed

The complete AI governance stack

Three layers that work independently or as a unified platform. Start with one operator, grow into the full stack.

Shield & Guardrails

Compliance middleware that intercepts every LLM request and response. PII detection, data classification routing, topic enforcement, prompt injection defense, and full audit logging.

Coming soon

Palena Shield

LiteLLM callback middleware that orchestrates 9 modular guardrails in sequence. Fail-closed or fail-open modes.

Apache 2.0PythonLiteLLM callback
Available

Pseudonymizer

Replaces real entity names with consistent fictitious ones using Presidio. Session-aware across multi-turn conversations.

Apache 2.0PIIPresidioRedis
View documentation
Coming soon

Data Classification

Detects confidential content and auto-routes to self-hosted models. Level 4 (restricted) is blocked entirely.

Apache 2.0RoutingCompliance

MCP Servers

Enterprise-grade tool servers for AI agents. Each server enforces policy, scans for PII, and produces auditable provenance records.

Available

WebSearch MCP

5-stage pipeline: SearXNG search, tiered scraping (L0/L1/L2), Presidio PII scan, pluggable reranking, and provenance hashes.

Apache 2.0GoMCP
View documentation
Coming soon

Docs MCP

RAG over internal documents with pgvector/Qdrant, hybrid search, and source-level citations. Documents never leave your infra.

Apache 2.0GoRAG
Coming soon

Sandbox MCP

Secure code execution in gVisor/Kata sandboxes via kubernetes-sigs/agent-sandbox. Warm pools for sub-second allocation.

Apache 2.0GogVisor

How it works

One PalenaGateway CR deploys a complete enterprise AI platform. Palena orchestrates the sub-operators — it never reimplements their logic.

PalenaGateway CR

You define this. Everything else is automated.

Palenareconciles

Infrastructure

CloudNativePG

Redis

ClickHouse

AI Gateway

LiteLLM Operator

Models & Teams

Config Sync

Compliance

Shield + Guardrails

Policy Engine

Audit Trail

Agent Tools

WebSearch MCP

Docs MCP

Sandbox MCP

Without Palena, a platform engineer manually configures 20+ cross-references between 10+ components.
One misconfigured secret reference breaks the entire platform.

1

Custom Resource

10+

Components deployed

20+

Auto-wired references

9

Guardrails

Built for regulated industries

Every feature exists because a compliance officer, security team, or platform engineer needed it.

Bidirectional Config Sync

Admin UI and GitOps coexist. The LiteLLM Operator syncs between CRD specs and the LiteLLM API — changes from either side are reconciled without conflict.

PII Pseudonymization

Presidio-powered entity detection with session-aware pseudonym mapping. Real names never reach cloud LLMs. Automatic reversal in responses.

Data Classification Routing

Confidential content is auto-routed to self-hosted models. Restricted content is blocked entirely. Classification level travels with the request.

Policy-as-Code

Centralized governance via OPA or YAML rules. Every tool call, every model request goes through policy evaluation. Deny-wins model.

Content Provenance

Three-stage SHA-256 hash chain from raw HTML through extraction to final content. Every search result is verifiable and auditable.

Platform Compatibility

Tested on vanilla K8s, OpenShift, EKS, AKS, GKE, and k3s. OpenShift Routes, SCCs, and air-gapped ImageStreams supported natively.

Full Audit Trail

Every LLM interaction, tool call, PII detection, and policy evaluation logged to ClickHouse with configurable retention up to 7 years.

Secure Agent Tooling

MCP servers for search, documents, code execution, and vault access — all behind policy gates with PII scanning and audit logging.

Open source, enterprise ready

Every Palena component is licensed under Apache 2.0 — the most enterprise-friendly open source license. No copyleft restrictions, no surprises.

Apache License 2.0

All components — operators, platform, and tools

Use freely in commercial projects
Explicit patent grant included
Modify and distribute without restriction
No copyleft obligations
Enterprise legal teams approve it
Contribute back on your own terms

Deploy compliant AI infrastructure today

Start with a standalone operator or deploy the full platform. Join the community building enterprise AI governance for Kubernetes.

$helm install litellm-operator palena/litellm-operator