If your platform is built on Kubernetes and open standards, you’ll want your agent infrastructure to match. A cloud-native agent gateway runs where your workloads already run, expresses configuration the way your team already works, scales horizontally, and leans on open protocols like MCP and A2A rather than a proprietary runtime. As agents move into production on cloud-native stacks, a healthy set of gateways and frameworks has emerged that treat agent connectivity as just another layer of your infrastructure.
This guide ranks five cloud-native options for teams that want agent governance to fit their Kubernetes-first, open-standards world.
What cloud-native teams should weigh
The priorities: genuinely cloud-native deployment (containers, the Kubernetes Gateway API, GitOps); support for open agent protocols (MCP, A2A) so you’re not locked in; routing, guardrails, and observability that plug into your existing stack; high throughput and low latency; and the ability to run it yourself. The five below all fit cloud-native environments; they differ in whether they’re a gateway, a framework, or a broader platform, and in how much governance ships in.
1. TrueFoundry — a cloud-native agent control plane you run yourself
TrueFoundry leads because it delivers cloud-native operation and a purpose-built agent control plane at once. Its Agent Gateway runs in your own cloud and Kubernetes environment and governs agents, tools, and models together, with an agent registry, per-hop observability, guardrails, and least-privilege access, all framework-neutral so it fits whatever agent stack your teams choose. Its agent harness, TrueForge, is open source and vendor-neutral, which suits teams that want to inspect and extend the core.
The result is that a cloud-native platform team gets one system for agent governance instead of assembling several, without giving up self-hosting. The design is covered in TrueFoundry’s agent harness documentation. For teams that want cloud-native and governed in equal measure, it’s the most complete option.
Best for: cloud-native teams wanting a governed, framework-neutral agent control plane they run themselves. Watch-out: it’s a platform, so more than a minimal proxy.
2. Kagent — open-source agents, Kubernetes-native
Kagent, a CNCF project from Solo.io, is the first open-source agentic framework built specifically for Kubernetes. Agents run directly in clusters, defined declaratively the Kubernetes way, built on MCP and AutoGen, and it supports LangChain, CrewAI, Google ADK, A2A, and custom frameworks under unified governance, with tools for Argo, Helm, Istio, and more. For platform teams that want agents to be first-class cluster citizens, it’s the natural cloud-native choice.
Best for: Kubernetes teams that want open-source, cluster-native agents. Watch-out: a younger project, so check maturity of specific features.
3. Arch (archgw) — an AI-native agent data plane
Arch, from Katanemo, is an open-source, models-native proxy for agents built by the team behind a widely used high-performance proxy, which makes it deeply cloud-native. It handles agent routing and hand-off, guardrails, jailbreak detection, and prompt-to-tool conversion, with unified LLM access and zero-code logs and traces built on open standards. For teams that want agent connectivity handled in a familiar, high-performance data plane, it’s a strong, lightweight core.
Best for: teams wanting a high-performance, AI-native agent data plane. Watch-out: it’s a focused data plane, so add higher-level management around it.
4. Higress — high-throughput, AI-native gateway
Higress, built on Istio and Envoy and open-sourced under Apache-2.0, is a cloud-native gateway hardened at large scale inside Alibaba. It hosts MCP servers for agent tool use, unifies LLM and MCP API management, supports WAF and many authentication strategies, and handles very high throughput with millisecond configuration changes. For cloud-native teams whose priority is performance and reliability across agent and tool traffic, it’s a proven core.
Best for: cloud-native teams needing high-throughput agent and tool traffic handling. Watch-out: higher-level agent governance is lighter than a dedicated control plane.
5. Portkey — a cloud-native gateway with an open core
Portkey rounds out the list as a widely used gateway with an open-source core that runs cloud-native and extends to agent and tool traffic. It brings routing, guardrails, observability, and cost controls to the calls agents make, and its MCP support governs tool use, so teams already running it for models can add agent oversight in the same place. Several enterprise-grade features sit in the hosted or enterprise tier, so confirm what you need is in the open build.
Best for: teams that want a cloud-native gateway with an open core spanning models, tools, and agents. Watch-out: check the open-versus-enterprise feature split.
How to choose
If you want agents as native Kubernetes citizens, Kagent is purpose-built, while Arch and Higress give you high-performance data planes, and Portkey is a cloud-native gateway with an open core. But if you want cloud-native deployment plus a governed, framework-neutral agent control plane, running in your own cluster, TrueFoundry leads.
The bottom line
Cloud-native teams should expect agent infrastructure to fit their world: Kubernetes-native, open-standards-based, and self-hostable. Each option here does that well. The one that pairs cloud-native operation with complete, framework-neutral agent governance is TrueFoundry, which is why it’s the one to beat.

