Correction: I withdraw the proposed custom AgentDefinition YAML. kagent already has a native Kubernetes Agent/SandboxAgent manifest for role, model and tools; Goose has a native Recipe YAML. We should test these actual schemas against k3s, access control and chat before designing any new format.
Existing agent formats come first
The earlier illustrative agents/<name>.yaml used invented fields. It is withdrawn as a working proposal. The requirement is to use an existing format as written and only consider a new language if the available formats fail a concrete test.
kagent 0.x, marked current in its documentation: kagent.dev/v1alpha2 Agent is a real Kubernetes CRD. spec.declarative carries modelConfig, systemMessage, named MCP tool bindings and deployment settings. SandboxAgent uses the same declarative agent specification on Agent Substrate and adds spec.sandbox.network.allowedDomains for outbound access. A2A can connect a communication adapter without making kagent the team's task board. These are product fields, not a proposed schema. Sources: https://kagent.dev/docs/kagent/ ; https://kagent.dev/docs/kagent/0.x/concepts/agents/ ; https://kagent.dev/docs/kagent/0.x/resources/api-ref/ ; https://kagent.dev/docs/kagent/0.x/examples/agent-substrate/ ; https://kagent.dev/docs/kagent/0.x/examples/slack-a2a/
kagent 1.x, marked alpha: the native resources change to AgentTemplate for role, model and MCP tool bindings, and Harness for runtime, image, WorkerPool and admission of templates. An AgentInstance is a conversation session, not a task record. The installation guide currently requires Kubernetes 1.37+, a manually enabled certificate API, Agent Substrate, PostgreSQL and snapshot storage. It is a candidate to evaluate against the actual k3s version, not a drop-in choice. Its open-source gRPC endpoint does not verify caller identity, so a trusted bridge and network isolation are necessary. Sources: https://kagent.dev/docs/kagent/1.x/get-started/your-first-agent/ ; https://kagent.dev/docs/kagent/1.x/setup/installation/ ; https://kagent.dev/docs/kagent/1.x/substrate-runtime/identity/ ; https://kagent.dev/docs/kagent/1.x/reference/versions/
Goose Recipe: a ready YAML format with instructions, model settings, MCP extensions, and per-extension available_tools. It can run headlessly, but it is a recipe for an agent execution, not a Kubernetes controller or complete security policy. Sources: https://github.com/aaif-goose/goose/blob/main/documentation/docs/guides/recipes/recipe-reference.md ; https://github.com/aaif-goose/goose/blob/main/documentation/docs/guides/running-tasks.md
Selection should compare the native files and documented behavior, including real access enforcement, local debugging, chat invocation and k3s compatibility. No proprietary intermediate agent YAML is justified yet.