Namespaces & Apps
Every application in this fleet runs in its own isolated area (a Kubernetes namespace) — deleting or rebuilding one app can’t accidentally touch another’s data. One shared area holds only the cross-cutting login infrastructure every app’s routes reference, nothing app-specific of its own.
Current namespace inventory
| Namespace | Workload | Notes |
|---|---|---|
Shared gateway |
Login gate + shared routing config |
No application resources of its own. |
Agents router |
Bundles the weather/time/currency agents behind one address for the orchestrator to delegate to |
No shared LLM/TTS proxy exists anymore — see LLM Gateway. |
Shared database |
The fleet’s shared Postgres instance (currently used by the podcast pipeline’s three shows) |
See Storage. |
Tracing |
LLM call tracing and debugging |
Own login. Currently receives no new traces — see Langfuse. |
Logs |
Cross-pod log retention and search |
See Observability. |
Dashboard |
Internal index of the other apps |
Behind the shared login. |
Documentation |
This site |
Behind the shared login, like the internal tool set. |
Podcast agent |
Collects stories and publishes episodes on a schedule, for all three shows (tech, stock, malayalam) |
No public route at all. See Podcast Agent — Overview. |
Podcast feed |
Serves the public podcast episodes and RSS feed, for all three shows |
No login — a podcast app can’t complete one. |
Podcast dashboard |
Read-only view over the podcast pipeline’s data, for all three shows |
Behind the shared login. See Podcast Agent — Overview and Internal Tooling Behind SSO. |
Weather, time, currency agents |
Small single-purpose internal agents, run together behind the agents router above |
No public route at all — see below. |
Orchestrator agent |
Delegates to the three agents above via the agents router; its own reasoning calls the outside AI provider directly |
No public route at all — see below. |
Network isolation is real, not just documentation
Several of the boundaries above matter because network policy actually enforces them, not just because they’re written down this way. The weather/time/currency agents are reachable only from the orchestrator agent, through the agents router — nothing else in the cluster can reach them, enforced at the network level. The podcast pipeline’s own inbound traffic is similarly reachable only by whatever legitimately triggers it (the orchestrator agent, for the tech show’s conversational trigger). See LLM Gateway and The Agent Fleet.
A shared-storage exception
The podcast pipeline and the app that serves its public feed are the one pair of apps that share data without talking to each other over the network — a shared storage volume instead. See Storage and Podcast Agent — Storage & Feed.