Namespaces & Apps

Every application in this fleet runs in its own isolated area (a Kubernetes namespace) — deleting or rebuilding one app can’t accidentally touch another’s data. One shared area holds only the cross-cutting login infrastructure every app’s routes reference, nothing app-specific of its own.

Current namespace inventory

Namespace Workload Notes

Shared gateway

Login gate + shared routing config

No application resources of its own.

Agents router

Bundles the weather/time/currency agents behind one address for the orchestrator to delegate to

No shared LLM/TTS proxy exists anymore — see LLM Gateway.

Shared database

The fleet’s shared Postgres instance (currently used by the podcast pipeline’s three shows)

See Storage.

Tracing

LLM call tracing and debugging

Own login. Currently receives no new traces — see Langfuse.

Logs

Cross-pod log retention and search

See Observability.

Dashboard

Internal index of the other apps

Behind the shared login.

Documentation

This site

Behind the shared login, like the internal tool set.

Podcast agent

Collects stories and publishes episodes on a schedule, for all three shows (tech, stock, malayalam)

No public route at all. See Podcast Agent — Overview.

Podcast feed

Serves the public podcast episodes and RSS feed, for all three shows

No login — a podcast app can’t complete one.

Podcast dashboard

Read-only view over the podcast pipeline’s data, for all three shows

Behind the shared login. See Podcast Agent — Overview and Internal Tooling Behind SSO.

Weather, time, currency agents

Small single-purpose internal agents, run together behind the agents router above

No public route at all — see below.

Orchestrator agent

Delegates to the three agents above via the agents router; its own reasoning calls the outside AI provider directly

No public route at all — see below.

Network isolation is real, not just documentation

Several of the boundaries above matter because network policy actually enforces them, not just because they’re written down this way. The weather/time/currency agents are reachable only from the orchestrator agent, through the agents router — nothing else in the cluster can reach them, enforced at the network level. The podcast pipeline’s own inbound traffic is similarly reachable only by whatever legitimately triggers it (the orchestrator agent, for the tech show’s conversational trigger). See LLM Gateway and The Agent Fleet.

A shared-storage exception

The podcast pipeline and the app that serves its public feed are the one pair of apps that share data without talking to each other over the network — a shared storage volume instead. See Storage and Podcast Agent — Storage & Feed.