Glossary

Terms used throughout this site, in the sense specific to this platform.

A2A

Agent-to-Agent protocol (a2a-protocol.org) — the JSON-RPC message/send surface every agent in the fleet exposes alongside its OpenAI-compatible one, backed by the official a2a-sdk.

Agents router

The small internal process that bundles the weather, time, and currency agents behind one address for the orchestrator agent to delegate to — replaced part of LiteLLM’s job when LiteLLM was removed. See Agents Router.

CronJob vs. Deployment (podcast-agent)

podcast-agent ships both, covering all three of its shows. The Deployment serves steady-state chat/A2A traffic (tech show only) plus on-demand HTTP triggers (any show); the CronJobs do the actual scheduled work (hourly ingest, daily generation, per show). See Podcast Agent — Ingest, History & Ranking.

forwardAuth

Traefik’s mechanism for delegating an auth decision to an external service before routing a request — here, the oauth-auth Middleware calls oauth2-proxy’s /oauth2/auth. See Authentication.

IngressRoute

Traefik’s own CRD for declaring routes — this org uses no Ingress resource and no cert-manager anywhere; every public route is one (or two — see the web/websecure split below) IngressRoute.

LiteLLM

The fleet’s former shared internal LLM gateway/proxy — every agent’s own reasoning calls, every TTS call, and every other app’s LLM traffic used to go through it. Removed 2026-08-25 to reclaim the memory it cost on this fleet’s single small machine; every consumer now calls its outside provider directly instead. See LLM Gateway.

local-path

K3s’s bundled default StorageClass — hostPath-backed, WaitForFirstConsumer. Every PVC in this fleet uses it, including the fleet’s shared Postgres instance. See Storage.

Session (Langfuse)

A grouping of LLM/TTS calls in Langfuse’s trace UI. Used to be driven by a metadata.session_id field LiteLLM forwarded on every call; since LiteLLM’s removal nothing feeds Langfuse new traces. See Langfuse.

web / websecure

Traefik’s two entrypoints (plain HTTP on 80, TLS on 443). Every protected route in this fleet ships as two separate IngressRoute objects — one per entrypoint — because a tls: block on a combined route silently breaks the web side. See Ingress & TLS.