Portus
A Rust-based Kubernetes gateway that carries HTTP, LLM and MCP traffic on one data plane with full Gateway API conformance.
At a Glance
Self-hosted Portus gateway (Gateway API, AI gateway and MCP gateway) released under the Apache License 2.0.
Engagement
Available On
Listed Oct 2026
About Portus
Portus is an open-source Kubernetes gateway written in Rust by the Portus-Gateway organization. It implements the Gateway API and adds an AI gateway for LLM providers and an MCP gateway for tool servers, all on one data plane. The current release listed is v0.2.12, which adds a standalone mode with ACME certificates.
What It Is
Portus is an API and AI gateway for Kubernetes. A controller watches Gateway API and Portus CRDs, provisions a data plane per Gateway, and compiles configuration into a protobuf message streamed to each data plane over mTLS gRPC. The project reports passing 130 of 130 Gateway API v1.6.2 conformance tests (experimental channel) across the HTTP, GRPC, TLS, TCP and UDP profiles, with no skips.
AI and MCP Gateway
Clients that speak the Anthropic Messages or OpenAI chat API can point at Portus. The gateway routes on the request body (model, stream), swaps client keys for provider credentials, meters tokens from JSON and streamed responses, and enforces token budgets. A companion ledger issues portus_sk_ keys, stores only hashes, and keeps budgets and usage, and it stays off the request path. Claude Code can be used by setting its base URL and key.
The MCP gateway handles Streamable HTTP servers. It routes on the JSON-RPC method and tool name, federates several servers as <server>.<tool>, supports per-key tool allow lists and call budgets, and accepts OAuth bearer tokens from an OIDC issuer such as dex.
Policies and Design
Twelve policy CRDs cover timeouts, retries, rate limits, circuit breakers, connection caps, health checks, CORS, IP allow lists, body size limits, Basic auth and API-key auth, plus AI usage budgets. Config changes swap atomically so reloads do not drop connections. Network-stack logic sits in a stack-independent core; Rama 0.4 is the default since 0.2.4, with Pingora 0.9 selectable.
Performance Claims
The project publishes benchmarks using the howardjohn/gateway-api-bench method on a single Apple M4 VM, comparing Portus 0.2.3 with agentgateway v1.5.0. It reports 126,070 req/s at 256 connections and a 0.35 ms p99 at 30,000 req/s. The authors note the numbers are comparable only with each other on the same machine.
Setup Path
Install requires Kubernetes 1.32+ and Helm 3.8+, applying the Gateway API CRDs and then the Helm chart. Images are published for linux/amd64 and linux/arm64. A standalone mode runs the data plane from one YAML file with built-in ACME certificates, hot reload and name-based backends, without a cluster.
Community Discussions
Be the first to start a conversation about Portus
Share your experience with Portus, ask questions, or help others learn from your insights.
Pricing
Open Source
Self-hosted Portus gateway (Gateway API, AI gateway and MCP gateway) released under the Apache License 2.0.
- Apache-2.0 licensed source code
- Gateway API v1.6.2 conformance: 130/130 tests
- AI gateway for LLM providers with token budgets and API keys
- MCP gateway for tool servers
- Installed via Helm on Kubernetes 1.32+
Capabilities
Key Features
- Gateway API v1.6.2 conformance (130/130)
- HTTPRoute, GRPCRoute, TLSRoute, TCPRoute, UDPRoute, ListenerSet, BackendTLSPolicy
- Twelve policy CRDs (timeouts, retries, rate limits, circuit breakers, CORS, auth)
- AI gateway with Anthropic and OpenAI dialects
- Token metering and budgets per key, user, tenant or route
- Ledger-issued API keys stored as hashes
- MCP gateway with tool-level routing and federation
- OAuth/OIDC bearer token verification
- Per-Gateway data plane provisioning
- Atomic config reloads without dropped connections
- Swappable network stack (Rama default, Pingora)
- Standalone mode with ACME certificates and hot reload
