# Portus

> A Rust-based Kubernetes gateway that carries HTTP, LLM and MCP traffic on one data plane with full Gateway API conformance.

Portus is an open-source Kubernetes gateway written in Rust by the Portus-Gateway organization. It implements the Gateway API and adds an AI gateway for LLM providers and an MCP gateway for tool servers, all on one data plane. The current release listed is v0.2.12, which adds a standalone mode with ACME certificates.

## What It Is

Portus is an API and AI gateway for Kubernetes. A controller watches Gateway API and Portus CRDs, provisions a data plane per Gateway, and compiles configuration into a protobuf message streamed to each data plane over mTLS gRPC. The project reports passing 130 of 130 Gateway API v1.6.2 conformance tests (experimental channel) across the HTTP, GRPC, TLS, TCP and UDP profiles, with no skips.

## AI and MCP Gateway

Clients that speak the Anthropic Messages or OpenAI chat API can point at Portus. The gateway routes on the request body (`model`, `stream`), swaps client keys for provider credentials, meters tokens from JSON and streamed responses, and enforces token budgets. A companion ledger issues `portus_sk_` keys, stores only hashes, and keeps budgets and usage, and it stays off the request path. Claude Code can be used by setting its base URL and key.

The MCP gateway handles Streamable HTTP servers. It routes on the JSON-RPC method and tool name, federates several servers as `<server>.<tool>`, supports per-key tool allow lists and call budgets, and accepts OAuth bearer tokens from an OIDC issuer such as dex.

## Policies and Design

Twelve policy CRDs cover timeouts, retries, rate limits, circuit breakers, connection caps, health checks, CORS, IP allow lists, body size limits, Basic auth and API-key auth, plus AI usage budgets. Config changes swap atomically so reloads do not drop connections. Network-stack logic sits in a stack-independent core; Rama 0.4 is the default since 0.2.4, with Pingora 0.9 selectable.

## Performance Claims

The project publishes benchmarks using the howardjohn/gateway-api-bench method on a single Apple M4 VM, comparing Portus 0.2.3 with agentgateway v1.5.0. It reports 126,070 req/s at 256 connections and a 0.35 ms p99 at 30,000 req/s. The authors note the numbers are comparable only with each other on the same machine.

## Setup Path

Install requires Kubernetes 1.32+ and Helm 3.8+, applying the Gateway API CRDs and then the Helm chart. Images are published for linux/amd64 and linux/arm64. A standalone mode runs the data plane from one YAML file with built-in ACME certificates, hot reload and name-based backends, without a cluster.

## Features
- Gateway API v1.6.2 conformance (130/130)
- HTTPRoute, GRPCRoute, TLSRoute, TCPRoute, UDPRoute, ListenerSet, BackendTLSPolicy
- Twelve policy CRDs (timeouts, retries, rate limits, circuit breakers, CORS, auth)
- AI gateway with Anthropic and OpenAI dialects
- Token metering and budgets per key, user, tenant or route
- Ledger-issued API keys stored as hashes
- MCP gateway with tool-level routing and federation
- OAuth/OIDC bearer token verification
- Per-Gateway data plane provisioning
- Atomic config reloads without dropped connections
- Swappable network stack (Rama default, Pingora)
- Standalone mode with ACME certificates and hot reload

## Integrations
Kubernetes, Helm, Gateway API, Anthropic, OpenAI, Claude Code, Model Context Protocol, dex, Let's Encrypt, Rama, Pingora, Docker Compose

## Platforms
LINUX, CLI, API

## Pricing
Open Source

## Version
0.2.12

## Links
- Website: https://portus-gateway.dev
- Documentation: https://github.com/Portus-Gateway/Portus/tree/main/docs
- Repository: https://github.com/Portus-Gateway/Portus
- EveryDev.ai: https://www.everydev.ai/tools/portus
