Deploying Kilo¶
Kilo is an open-source AI coding agent; its CLI (@kilocode/cli) is a fork of OpenCode. The kilo runtime runs the Kilo TUI inside tmux behind a browser terminal, and is installed by the language-operator-runtimes chart. No Kilo account is needed: every model call goes through the cluster's model gateway.
The runtime image is built in kilo-adapter on the shared coding-runtime base, like the Claude Code and OpenCode runtimes.
Prerequisites¶
- Language Operator v0.3.14 or later installed, including the
language-operator-runtimeschart (provides thekiloruntime). Kilo calls the gateway's/v1/responsesendpoint; earlier gateways served it only for hosted providers, not foropenai-compatiblemodels such as Ollama. - A
LanguageClusterto deploy into, with yourkubectlcontext set to its namespace (examples below assume a cluster nameddemo-cluster) - An LLM provider API key, or a local model endpoint (e.g. Ollama)
Instructions¶
Configure a Model¶
kubectl create secret generic anthropic-credentials \
--from-literal=api-key=sk-ant-your-key-here
kubectl apply -f - <<EOF
apiVersion: langop.io/v1alpha1
kind: LanguageModel
metadata:
name: claude-sonnet
spec:
provider: anthropic
modelName: claude-sonnet-4-5
apiKeySecretRef:
name: anthropic-credentials
key: api-key
EOF
Deploy Kilo¶
kubectl apply -f - <<EOF
apiVersion: langop.io/v1alpha1
kind: LanguageAgent
metadata:
name: kilo
spec:
runtime: kilo
models:
- name: claude-sonnet # or gpt-4o, llama3
EOF
On start, the runtime writes Kilo's config (kilo.jsonc) from the operator's /etc/agent/config.yaml: the first referenced model, reached through the gateway, and every LanguageTool the agent references, as a remote MCP server. spec.instructions, when set, is loaded as standing context for every session. Kilo's telemetry, session upload, sharing and auto-update are turned off.
Verify¶
Wait for PHASE to reach Running. The MODE column shows service: the TUI is long-lived and addressable. See
Execution Modes.
Connect¶
Access is gated by the cluster's OIDC proxy — there is no separate Kilo password.
If your LanguageCluster has a domain and auth enabled,
open https://kilo.demo-cluster.\<your-domain> and sign in through the cluster's OIDC provider.
For local access, port-forward the service (this bypasses the proxy, so no login is required):
Then open http://localhost:8080 in your browser. The session lives in tmux, so it survives page reloads, and after a pod restart Kilo resumes the previous conversation from the workspace volume.
Warning
The terminal has no built-in authentication. When the cluster does not enable auth, it is exposed unauthenticated on its ingress. Enable cluster auth to protect it.
Task Mode¶
Kilo also runs headless as a task: each run does the work in spec.instructions and exits.
apiVersion: langop.io/v1alpha1
kind: LanguageAgent
metadata:
name: changelog
spec:
runtime: kilo
models:
- name: claude-sonnet
repository:
url: https://github.com/acme/api.git
instructions: |
Summarise the commits merged since the last tag into CHANGELOG.md.
execution:
mode: task
schedule: "0 6 * * 1" # or omit it and run on demand with argo submit
Each run executes kilo run --auto --format json with the instructions as the prompt. --auto approves every permission Kilo would otherwise ask for, since nobody is there to answer. The exit code is the run's result: 0 is Succeeded; 1 is Failed, for example on an unknown model or an unreachable gateway. An agent with no instructions fails before Kilo starts.
Gateway Credentials¶
The operator gives every agent its own gateway key as MODEL_API_KEY, and Kilo sends it on every model call, so there is nothing to configure. The gateway rejects calls without a valid key and attributes each one to the agent. See Gateway authentication.
What the Operator Created¶
| Resource | Name | Purpose |
|---|---|---|
| WorkflowTemplate | kilo |
The agent's pod spec; also what argo submit --from targets |
| Workflow | kilo |
The long-lived run. Runs the Kilo WebSocket terminal container |
| Service | kilo |
ClusterIP on port 8080 |
| NetworkPolicy | kilo |
Allows inbound from other agents in this namespace |
| PVC | kilo-workspace |
10Gi persistent workspace |
| ConfigMap | kilo-agent |
Injected at /etc/agent/config.yaml |
A task-mode agent gets a CronWorkflow (when it has a schedule) instead of the long-lived Workflow, and no Service.