The Question
Can a complete software development lifecycle, from dev desktop to shipped app, run entirely inside Orion, with the coding agent itself running as a platform workload rather than SSH'd in from a laptop with cluster-admin?
The target was Argenova CRM: a Next.js app with an embedded Postgres database and a chat interface wired to a Hermes Agent on the same cluster, answering natural-language questions about live company data. Ask "what's our open pipeline?" and it answers from the database, not model memory.
What the Agent Did
The distinguishing feature: the coding agent was itself a workload. A Claude Code instance ran as a Terminal workload with a Kubernetes Role scoped to the project namespace. From inside that boundary it set up the developer desktop, scaffolded the app, seeded the database, and debugged everything that broke, with kubectl powers that end exactly at the namespace edge.
Concrete moments from that loop: it diagnosed an NFS file-ownership break and rebuilt the app directory as the desktop user, caught an ImagePullBackOff and spotted that a registry token had been pasted where a Secret name belonged, and patched a live Ingress path to kill a redirect loop, then fed the fix back into the plugin chart.
How Orion Made It Possible
Project storage survives everything. Code written to project-persistent storage survived hibernation, pod restarts, and a full replacement of the workstation workload mid-project with zero data loss. One idempotent bootstrap command rebuilds the rest: two to three minutes cold, seconds warm. Hibernated, the dev environment costs nothing.
The app shipped as a native plugin in the same format as Orion's official plugins: a marketplace descriptor, a launch-time field schema, and an embedded Helm chart. First launch pulled the private image, initialized Postgres, and served the dashboard behind session auth, with zero hand-applied manifests.
Agent permissions are a launch field. Choosing none, read-only, or namespace-admin turns "how much can the AI touch" into a one-select decision, enforced by Kubernetes Roles rather than prompt instructions. The coding agent could fix a broken Ingress but could not see another project's namespace.
The Results
A single working day, one developer plus one coding agent running as a cluster workload. Workspace and agent launched from the catalog in minutes. Environment setup, scaffolding, and the chat proxy took about an hour. Wiring and verifying the Hermes Agent API took another. Authoring, packaging, and debugging the plugin to live took about two.
The whole lifecycle ran through the platform's plugin and GitOps path. No external CI/CD beyond image builds, and no manual Kubernetes manifests applied by hand. Asked which customer churned and what the lost deal was worth, the deployed app's agent answered from live Postgres.
AT A GLANCE
FIELD
Agentic Development
DEPLOYMENT
Customer-hosted
ABOUT
An internal Juno Innovations build: Argenova CRM, a Next.js app with an embedded Postgres database and a chat interface wired to a Hermes Agent on the same cluster.

