AI Platform Control-Boundary Guide AI 平台控制边界指南

Portkey vs TrueFoundry
Managed Gateway or Private AI Platform?
Portkey 与 TrueFoundry:托管网关,还是私有 AI 平台?

Portkey offers a managed gateway-centered suite with routing, guardrails, observability, prompts, and administration. TrueFoundry spans managed gateway options, private gateway deployment, model and service deployment, agents, MCP, governance, and cloud infrastructure. The boundary matters more than the checklist.

Portkey 提供以托管网关为中心的路由、护栏、可观测性、提示词与管理套件;TrueFoundry 则横跨托管/私有网关、模型与服务部署、智能体、MCP、治理和云基础设施。控制边界比功能清单更重要。

Managed AI gateway suite compared with a private deployment and governance platform across a control boundary

TL;DR

Portkey favors managed gateway operations

Choose it when teams want routing, policy, guardrails, logs, traces, prompts, budgets, and administration without adopting a wider deployment platform.

TrueFoundry spans a wider platform boundary

Choose it when the same system must cover gateway planes, private networking, model deployment, agent workloads, MCP, governance, and cloud operations.

Self-hosting is not one checkbox

Separate data plane, gateway plane, control plane, compute plane, metadata stores, telemetry, secrets, upgrades, backup, and support responsibility.

Start with control boundaries

Decide what must stay in the VPC, what may be SaaS, who can push policy, and which team owns outages before comparing features.

Portkey 偏向托管网关运营

适合希望获得路由、策略、护栏、日志、追踪、提示词、预算与管理,但不想采用更广部署平台的团队。

TrueFoundry 覆盖更广平台边界

适合同一系统需要覆盖网关平面、私有网络、模型部署、智能体工作负载、MCP、治理和云运营的组织。

自托管不是一个复选框

应分别明确数据面、网关面、控制面、计算面、元数据存储、遥测、密钥、升级、备份和支持责任。

从控制边界开始

在比较功能前,先决定什么必须留在 VPC、什么可用 SaaS、谁能发布策略、哪个团队负责故障。

Managed suite and deployment platform are different scopes 托管套件与部署平台是不同范围

Portkey's core is a gateway-centered production suite. Official documentation covers a universal API gateway, routing configs, guardrails, observability, prompt management, budgets, limits, administration, and an open-source gateway path.

Portkey 的核心是以网关为中心的生产套件。官方文档覆盖通用 API 网关、路由 Config、护栏、可观测性、提示词管理、预算、限额、管理和开源网关路径。

TrueFoundry's scope includes deployment and infrastructure boundaries. Current documentation describes managed global gateway, deployable gateway plane, full control and compute planes, model and service deployment, agent and MCP access, governance, key management, monitoring, cloud-agnostic installation, and Kubernetes-oriented operations.

TrueFoundry 的范围包含部署与基础设施边界。当前文档描述托管全球网关、可部署网关 Plane、完整 Control/Compute Plane、模型与服务部署、智能体/MCP 访问、治理、密钥管理、监控、云中立安装和 Kubernetes 运营。

Portkey vs TrueFoundry side by side Portkey 与 TrueFoundry 并排比较

Decision surface 决策面 Portkey TrueFoundry
Primary scope 主要范围 Managed gateway, guardrails, observability and prompt operations 托管网关、护栏、可观测性与提示词运营 AI gateway plus deployment, agents, MCP and infrastructure governance AI 网关加部署、智能体、MCP 与基础设施治理
Control boundary 控制边界 SaaS-centered suite with gateway self-host options to validate 以 SaaS 为中心,需验证网关自托管选项 Managed SaaS gateway, deployable gateway plane, or broader self-host platform 托管 SaaS 网关、可部署网关面或更广自托管平台
Model lifecycle 模型生命周期 Route and govern calls to providers 路由并治理对供应商的调用 Deploy and operate models/services in addition to routing 除路由外还可部署运营模型与服务
Agent and tools 智能体与工具 Gateway and MCP capabilities within the suite 套件内的网关与 MCP 能力 Agent runtime, model gateway and MCP gateway within platform scope 平台范围内的智能体 Runtime、模型网关与 MCP 网关
Operations 运营 Vendor-managed product with configuration and integration work 厂商托管产品,团队负责配置与集成 Potential responsibility for clusters, planes, storage, upgrades and DR 可能需负责集群、各平面、存储、升级与灾备
Best owner 最佳负责人 AI platform, security and application enablement AI 平台、安全与应用赋能团队 Platform engineering, ML platform and cloud infrastructure 平台工程、ML 平台与云基础设施团队

Choose the smallest platform that owns the boundary 选择能覆盖边界的最小平台

Choose Portkey when

A managed gateway suite satisfies routing, guardrail, observability, prompt, budget and administrative needs without adding model-hosting operations.

Choose TrueFoundry when

Private deployment, model and service hosting, agent runtime, MCP, Kubernetes, cloud governance, or a wider AI platform roadmap are required.

Pause when

The proposal says “self-hosted” without a component diagram, sizing, upgrade model, backup design, support boundary, or tested recovery objective.

这些情况选 Portkey

托管网关套件已满足路由、护栏、可观测性、提示词、预算与管理需求,无需增加模型托管运营。

这些情况选 TrueFoundry

需要私有部署、模型/服务托管、智能体 Runtime、MCP、Kubernetes、云治理或更广 AI 平台路线。

这些情况先暂停

方案只写“自托管”,却没有组件图、容量、升级模式、备份设计、支持边界或已验证恢复目标。

Write a responsibility matrix for every plane 为每个平面编写责任矩阵

List gateway data plane, control plane, compute plane, UI and API, identity, policy store, secrets, telemetry, model registry, artifact storage, databases, queues, caches, DNS, certificates, backups and disaster recovery. For each component record location, owner, access path, data classification, scaling trigger, upgrade method, RPO, RTO and vendor support. Then compare deployment options.

列出网关数据面、控制面、计算面、UI/API、身份、策略存储、密钥、遥测、模型注册表、制品存储、数据库、队列、缓存、DNS、证书、备份与灾备。逐项记录位置、负责人、访问路径、数据分类、扩容触发、升级方式、RPO、RTO 与厂商支持,再比较部署选项。

Architecture rule: a private data plane is not the same as a private control plane or a fully self-hosted product.

架构规则:私有数据面不等于私有控制面,也不等于完整自托管产品。

A control-boundary proof 控制边界验证

  • Draw the exact SaaS, VPC, cluster and provider network paths, including metadata and telemetry egress.
  • Deploy one gateway instance, rotate secrets, update policy, upgrade, scale, back up and restore it using the documented operator path.
  • Run tools, structured output, streaming and forced failures while checking routing, guardrails, logs, traces, costs and audit records.
  • Test identity, private connectivity, tenancy, region and data-retention requirements with security stakeholders.
  • Calculate software plus cluster, storage, egress, on-call, upgrades, DR exercises and support.
  • 画出准确的 SaaS、VPC、集群与供应商网络路径,包括元数据和遥测出口。
  • 按文档化运营路径部署一个网关实例,并执行密钥轮换、策略更新、升级、扩容、备份与恢复。
  • 运行工具调用、结构化输出、流式和强制故障,并检查路由、护栏、日志、追踪、成本与审计记录。
  • 与安全团队共同验证身份、私有连接、租户、区域和数据保留要求。
  • 计算软件加集群、存储、出口、值班、升级、灾备演练与支持的成本。

Migrate policy, platform state and operator runbooks 迁移策略、平台状态与运营手册

Export providers, keys, models, routes, limits, budgets, guardrails, prompts, users, roles, logs, traces and costs. Also inventory deployment manifests, secrets, network policy, storage, dashboards, alerts, backups and runbooks. Dual-run one workload, reconcile policy and evidence, then complete an upgrade and rollback before moving the next team.

导出供应商、密钥、模型、路由、限额、预算、护栏、提示词、用户、角色、日志、追踪与成本;同时盘点部署清单、上游密钥s、网络策略、存储、仪表盘、告警、备份和 Runbook。双轨运行一个负载并核对策略与证据,完成一次升级和回滚后再迁移下一团队。

Deployment control and capability discovery are complementary 部署控制与能力发现互补

Portkey or TrueFoundry can govern model, gateway and platform traffic. QVeris complements that layer by helping agents discover external APIs, data and tools, and call them under controlled contracts and credentials. Preserve control-boundary metadata and trace context on every downstream capability invocation.

Portkey 或 TrueFoundry 可以治理模型、网关和平台流量;QVeris 作为互补层,帮助智能体发现外部 API、数据与工具,并在受控契约和凭证下调用。每次下游能力调用都应保留控制边界元数据与调用链上下文。

A Production Decision Scorecard for Portkey vs TrueFoundryPortkey 与 TrueFoundry的生产决策评分卡

For Portkey vs TrueFoundry, the useful question is not which product has more checkmarks. It is which design gives the team the right boundary, evidence, operating model, and exit path for a defined workload.

针对“Portkey 与 TrueFoundry”,真正有价值的问题不是哪款产品拥有更多勾选项,而是哪种设计能为明确工作负载提供正确边界、证据、运营模式和退出路径。

BOUNDARY
Score the primary job before features
先评估主要职责,再比较功能

Map inference gateway control versus a broader AI platform spanning deployment, infrastructure, governance, evaluation, and developer self-service. Decide which component owns each decision, where policy is enforced, and whether the products are substitutes, complements, or overlapping layers.

梳理推理网关控制与覆盖部署、基础设施、治理、评估和开发者自服务的更广 AI 平台。明确每项决策由哪个组件负责、策略在哪里执行,以及两者究竟是替代、互补还是部分重叠。

EVIDENCE
Benchmark one shared task corpus
使用同一任务语料做基准测试

To validate Portkey vs TrueFoundry, replay simple, long-context, streaming, structured-output, tool-calling, high-concurrency, and failure cases. Measure accepted-result quality, completion, p50 and tail latency, retries, trace completeness, and effective cost.

验证“Portkey 与 TrueFoundry”时,重放简单、长上下文、流式、结构化输出、工具调用、高并发和失败案例,衡量合格结果质量、完成率、常规与长尾延迟、重试、追踪完整性和实际成本。

OWNERSHIP
Price the operating model
计算运营模式的总成本

When evaluating Portkey vs TrueFoundry, include hosting, regional capacity, data retention, identity integration, policy maintenance, upgrades, incident response, support, compliance evidence, and the custom adapters the team must keep current.

评估“Portkey 与 TrueFoundry”时,纳入托管、区域容量、数据留存、身份集成、策略维护、升级、事故响应、支持、合规证据,以及团队必须持续维护的自定义适配器。

CHANGE
Test migration and rollback before selection
选型前先测试迁移与回滚

Before rolling out Portkey vs TrueFoundry, version a neutral request and evidence envelope, shadow traffic, classify semantic differences, preserve trace identity, and prove a staged rollback. Prefer the option that keeps policy and workload contracts portable.

上线“Portkey 与 TrueFoundry”前,版本化中立请求与证据封装,运行影子流量,分类语义差异,保留追踪身份,并证明可分阶段回滚。优先选择能让策略和工作负载契约保持可迁移的方案。

FAQ

Can Portkey be self-hosted?

Its documentation includes an open-source gateway and self-host paths; validate the exact components, edition, support and control-plane boundary you require.

Is TrueFoundry only an AI gateway?

No. Its documented platform scope also includes AI deployment, models, services, agents, MCP, governance and multiple installation patterns.

Which is faster to start?

A managed SaaS gateway usually reduces initial infrastructure work; the full answer depends on security review, integration, identity and data-boundary requirements.

Which gives more control?

Control must be decomposed into data, gateway, control and compute planes. Compare exact deployment contracts rather than the word “private.”

Portkey 能自托管吗?

其文档包含开源网关与自托管路径;应核对所需组件、版本、支持和控制面边界。

TrueFoundry 只是 AI 网关吗?

不是。其文档平台范围还包括 AI 部署、模型、服务、智能体、MCP、治理与多种安装模式。

哪个启动更快?

托管 SaaS 网关通常减少初始基础设施工作,但还取决于安全审查、集成、身份和数据边界要求。

哪个控制力更强?

应把控制拆成数据、网关、控制和计算平面;比较精确部署契约,而不是比较“私有”这个词。

Official sources and further reading 官方资料与延伸阅读