Glossary
Organization: the tenant unit inside the platform. All data belongs to exactly one organization, and access is checked against the caller’s organization on every request. Evaluation: a run that scores your AI product’s output against criteria you define, usually with a language model acting as the judge. Generation: producing test data: synthetic user scenarios, golden datasets, adversarial (red-teaming) test cases. Worker: a service that processes evaluation and generation jobs asynchronously, pulling them from a queue. This is the compute-heavy part of the platform. Worker pool: a set of workers. Shared pools process every organization’s jobs; dedicated pools are reserved for one organization. LLM gateway: the single outbound choke point for model calls. Handles provider routing, fallback, retries and quotas, so providers and models can be changed without touching the services. Helm chart: the packaging format for a Kubernetes application. Galtea publishes versioned charts you install withhelm install or through a GitOps controller.
ArgoCD: a GitOps controller that keeps a cluster in sync with configuration stored in
git. Galtea uses it internally; it is optional for a self-hosted install.
KEDA: a Kubernetes component that scales workloads on an external signal, in Galtea’s case
queue depth. Optional.
WireGuard: the encryption protocol used for the VPN tunnels in a private tenant.
NetBird: the open-source overlay network, built on WireGuard, used to give private access
to a tenant. Its control plane coordinates peers; it never carries application traffic.
Routing peer: a VPN peer that advertises whole network ranges, so a site reaches the
tenant without installing a client on every machine.
Egress control layer: the component all outbound traffic passes through in a private
tenant, enforcing a hostname allowlist that denies everything not explicitly approved.
Workload identity: a mechanism that lets a Kubernetes workload authenticate to cloud
services without a stored key.
Signed URL: a short-lived, single-object URL that lets a browser upload or download from
object storage directly, without the platform proxying the file.