The AI industry has largely focused on containers and Kubernetes as the foundation for modern AI platforms. But agentic AI introduces a fundamentally different challenge: running autonomous, tool-enabled software that can interact with systems, execute code, and make decisions on behalf of users. These are not just applications—they are untrusted workloads operating with unprecedented levels of access.In this episode, we explore why OpenStack is becoming a critical layer for safely operating agentic AI at scale. Drawing on real-world deployments supporting advanced AI infrastructure, we'll discuss how OpenStack's virtualization model provides stronger tenant isolation, encrypted storage, and fine-grained resource scheduling for GPUs and accelerators. We'll examine how technologies like Nova Scheduler, PCI passthrough, and Cyborg enable efficient allocation of high-performance AI hardware—including preserving high-speed NVLink connectivity between GPUs—while maintaining the security boundaries required in multi-tenant environments.The conversation also explores a growing architectural pattern: Kubernetes running AI applications on top of OpenStack virtual machines. While containers remain ideal for application delivery, OpenStack provides the infrastructure isolation layer needed when AI agents themselves become potential attack vectors. We'll discuss the tradeoffs between bare-metal Kubernetes, virtual machines, and emerging approaches such as Kata Containers, and why many operators view virtualization as the safer default for agentic workloads.As AI moves from inference to autonomous action, the question is no longer how to run models—it's how to securely run software you don't fully trust. This episode examines why OpenStack may already have the answer.
Information
- Show
- FrequencyUpdated Monthly
- PublishedJuly 28, 2026 at 2:00 PM UTC
- Length58 min
- Season1
- Episode4
- RatingClean
