> ## Documentation Index
> Fetch the complete documentation index at: https://trytilde.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy direct agents

> Connect an agent container straight to the Tilde gateway over an outbound HTTP/2 stream, with no inbound port and no provider keys.

A direct agent connects straight to the gateway. Start here unless you have a measured latency requirement that calls for [sidecars](/docs/deployment/sidecar-agents).

<Info>
  Direct agents require a [gateway](/docs/deployment/gateway): your own with Tilde OSS or Tilde Enterprise, or Tilde's with Tilde Cloud.
</Info>

<img src="https://mintcdn.com/tilde/UIZH9VuZaVUMv6QU/images/direct-agent.drawio.svg?fit=max&auto=format&n=UIZH9VuZaVUMv6QU&q=85&s=ad0d9fa7551818c25eb524ba7755747f" alt="A direct agent workload dialing out to the Tilde gateway, which forwards LLM requests to providers" width="1551" height="653" data-path="images/direct-agent.drawio.svg" />

<div className="zoom-hint"><Icon icon="magnifying-glass-plus" size={13} /> <em>Click to zoom</em></div>

Your agent container holds your code and the Tilde SDK, in TypeScript or Python. The SDK dials out to the gateway over HTTP/2. Wakes, tool calls, and telemetry uploads all travel on that one connection.

LLM requests also go to the gateway, which swaps in the real provider credentials and forwards them. The agent needs no inbound port, Kubernetes Service, or load balancer. It holds no provider API keys and needs no internet egress of its own.

## Where direct agents run

A direct agent is an ordinary container, so it runs wherever you run containers:

* **Kubernetes**, as a plain Deployment. It needs no Service or Ingress.
* **Managed container services**, such as Amazon ECS and Fargate.
* **Any Docker host.**

We recommend Kubernetes.

## What a direct agent needs

| Requirement | Detail |
| - | - |
| The Tilde SDK | TypeScript or Python. See [Anatomy of an agent](/docs/anatomy-of-an-agent). |
| A gateway address and a deployment token | Supplied as `TILDE_GATEWAY_URL` and `TILDE_DEPLOYMENT_TOKEN`. Keep the token in your secret manager. |
| Private network access to the gateway | Outbound only. The agent accepts no inbound connections. |

Every replica of a release uses the same deployment token, so you scale by adding replicas. Replicas finish their active invocations on shutdown, so rolling updates do not interrupt conversations.

Register each release from your pipeline. See [Release agents from CI](/docs/deployment/ci-cd).
