Glossary
Terms used throughout this site, in the sense specific to this platform.
- A2A
-
Agent-to-Agent protocol (a2a-protocol.org) — the JSON-RPC
message/sendsurface every agent in the fleet exposes alongside its OpenAI-compatible one, backed by the officiala2a-sdk. - Agents router
-
The small internal process that bundles the weather, time, and currency agents behind one address for the orchestrator agent to delegate to — replaced part of LiteLLM’s job when LiteLLM was removed. See Agents Router.
- CronJob vs. Deployment (podcast-agent)
-
podcast-agentships both, covering all three of its shows. The Deployment serves steady-state chat/A2A traffic (tech show only) plus on-demand HTTP triggers (any show); the CronJobs do the actual scheduled work (hourly ingest, daily generation, per show). See Podcast Agent — Ingest, History & Ranking. - forwardAuth
-
Traefik’s mechanism for delegating an auth decision to an external service before routing a request — here, the
oauth-authMiddleware calls oauth2-proxy’s/oauth2/auth. See Authentication. - IngressRoute
-
Traefik’s own CRD for declaring routes — this org uses no
Ingressresource and no cert-manager anywhere; every public route is one (or two — see theweb/websecuresplit below)IngressRoute. - LiteLLM
-
The fleet’s former shared internal LLM gateway/proxy — every agent’s own reasoning calls, every TTS call, and every other app’s LLM traffic used to go through it. Removed 2026-08-25 to reclaim the memory it cost on this fleet’s single small machine; every consumer now calls its outside provider directly instead. See LLM Gateway.
local-path-
K3s’s bundled default StorageClass — hostPath-backed,
WaitForFirstConsumer. Every PVC in this fleet uses it, including the fleet’s shared Postgres instance. See Storage. - Session (Langfuse)
-
A grouping of LLM/TTS calls in Langfuse’s trace UI. Used to be driven by a
metadata.session_idfield LiteLLM forwarded on every call; since LiteLLM’s removal nothing feeds Langfuse new traces. See Langfuse. web/websecure-
Traefik’s two entrypoints (plain HTTP on 80, TLS on 443). Every protected route in this fleet ships as two separate
IngressRouteobjects — one per entrypoint — because atls:block on a combined route silently breaks thewebside. See Ingress & TLS.