Agent Substrate + kagent

Run stateful AI agents on Kubernetes without a pod per agent.

AI agents spend most of their lives waiting. Agent Substrate is the open source runtime that checkpoints an agent, memory and filesystem included, and restores it on any free worker, so a small pool of pre-warmed pods can serve many isolated agent sessions. kagent turns it into a platform your teams can actually use.

Why agent substrate

Kubernetes was built for services that stay busy. Agents don't.

Agent Substrate is a runtime and scheduler that sits on Kubernetes and matches how agents actually behave: bursty, stateful and idle most of the time. It decides where each agent runs and keeps it cheap to hold.

Agents are idle most of the time

An agent fires a model call or a tool call, then waits on a person, an API or another agent. With a pod or sandbox per agent, each session holds its CPU and memory for its whole life, whether it's working or not.

Scaling pods is too slow for agents

Spinning up a fresh pod per session adds cold-start delay users can feel, and thousands of short-lived pods put real pressure on the control plane.

Agents need memory that survives

A restarted container loses what the agent had in memory. Agents need their full state saved and restored, not just a disk volume, so a session can pick up exactly where it left off.

~250

stateful actors on 8 pods in the project's reference demo

1,000

actors per worker by default

3

checkpoint modes: suspend, pause and revert

2

sandbox types: gVisor and microVMs

From the open source project's defaults and reference demo. The project is pre-1.0.

How it works

Many actors. A few warm workers. State that follows the agent.

Agent Substrate treats each agent session as an actor and keeps a small pool of ready workers. When an actor is called, its saved state is restored onto a free worker. When it's suspended, its memory and filesystem changes are checkpointed to object storage and the worker moves on. New actors start from a golden snapshot of their template instead of cold-booting.

Actors: many agent sessions Suspended actors live in object storage active suspended Substrate control plane assigns, snapshots, restores and routes each actor Workers: a few warm pods gVisor or microVM isolation Worker 1 · running actor A Worker 2 · running actor D Worker 3 · running actor G 1 · Request arrivesfor a suspended actor 2 · Restoreits RAM and filesystem onto a worker 3 · Route and runon any free worker 4 · Suspendto GCS or S3; free the worker

Agent Substrate with kagent

Substrate schedules agents. kagent makes them a platform.

Agent Substrate is a low-level runtime: actors, workers and APIs. kagent is the open source, Kubernetes-native layer on top that gives developers a way to build and ship agents, and gives platform teams a way to run them.

Declarative agents as Kubernetes resources

Define agents with kagent's Harness and AgentTemplate resources and ship them with GitOps, the same way you ship everything else. kagent handles the Substrate APIs.

Bring the framework you already use

Run agents built with LangGraph, Google ADK, Codex or Claude Code on Substrate, from the kagent UI or from code.

Worker pools that scale themselves

kagent manages Substrate worker pools across your nodes and scales them with demand, so platform teams don't hand-tune capacity.

Snapshots you can keep and fork

Substrate can tag snapshots and clone them into another tenant, so you can fork an agent from a known state. kagent snapshot policies put that to work, and Solo Enterprise for kagent adds context snapshots for reproducible debugging.

L7 policy, authorization and audit through agentgateway

Substrate's own egress controls match on hostname and port. agentgateway, already a routing option in Substrate's network layer, adds MCP- and A2A-aware policy, authentication and audit on top.

Observability built in

OpenTelemetry tracing and metrics, plus a Substrate dashboard in Solo Enterprise for kagent that shows which actors are running or idle.

One stack, each layer doing one job kagentAgent runtime and control plane: declarative agents, frameworks, UI, telemetry agentgatewayL7 policy for MCP and A2A, authorization, credentials and audit Agent SubstrateRuntime and scheduling: checkpoint, restore and place actors on workers SandboxKernel or hardware isolation: gVisor or microVMs All of it runs on standard Kubernetes. Purple layers are open source projects created by Solo.io.

Agent Substrate vs. OpenShell

Different layers, different strengths

Agent Substrate and NVIDIA OpenShell both isolate agents, so they get compared a lot. Substrate is the runtime underneath: it decides where an agent runs and keeps it cheap and stateful. OpenShell is strongest above that, controlling what an agent may do. Here's an honest look at both.

Agent Substrate
where an agent runs
NVIDIA OpenShell
what an agent may do
Agent stateCheckpoints memory, filesystem changes and durable directories to GCS or S3, then restores on any free worker. Suspend, pause and revert.A restart doesn't restore process memory. On Kubernetes, stopping a sandbox deletes the pod and keeps its disk volume.
DensityMany actors share a pool of pre-warmed workers, up to 1,000 per worker by default, autoscaled with HPA.One sandbox per agent for its whole life; two pods per sandbox on Kubernetes.
Fork from a known stateGolden snapshot per template; tagged snapshots can be cloned into another tenant.No equivalent.
Isolation boundarygVisor by default, or microVMs.Landlock and seccomp on the shared host kernel, or a libkrun VM.
Kubernetes control planeOwn CRDs and gRPC scheduler; per-actor state kept out of etcd.A driver on the SIG agent-sandbox CRD; each sandbox is a Kubernetes object.
Policy depthEgress matched on hostname and port.Per-binary OPA/Rego rules that understand REST, MCP, GraphQL and more, with formal verification of changes.
Credentials and auditPlaceholder secrets swapped at the proxy; authorization is experimental.Adds SigV4 re-signing, OAuth token exchange, Vault and OCSF audit logs.
Developer experienceKubernetes only; Go APIs.One-line local install on Docker, Podman or macOS; Python, TypeScript and Go SDKs.
GPUsTemporarily unsupported.Supported.
Project governanceOpen source, maintainers from Google and Solo.io, intended for CNCF.Open source, led by NVIDIA.

Highlighted cells show where each project is further along, based on each project's public code and docs as of October 2026. Agent Substrate's published performance figures are project targets; benchmark results haven't been published yet.

Agent Substrate

The runtime underneath

Substrate decides where an agent runs and keeps it cheap and stateful: checkpoint and restore, dense worker pools, forking and a strong isolation boundary.

OpenShell

Strong above that layer

OpenShell's strengths are in controlling what an agent may do: deep policy, credential handling, audit and an easy local developer setup.

kagent + agentgateway

Closing the gap on Substrate

Substrate's thinnest areas are L7 policy, authorization and audit. agentgateway is already a routing option in Substrate's network layer, and kagent makes Substrate usable day to day.

FAQ

Agent substrate questions, answered

The short answers to what teams ask most about Agent Substrate, kagent and sandboxing.

What is agent substrate?

Agent Substrate is an open source runtime and scheduler for running AI agents on Kubernetes. It maps many mostly idle agent sessions (actors) onto a smaller pool of pre-warmed pods (workers), checkpointing an agent's memory and filesystem to object storage and restoring it on any free worker.

Why can't I just run agents as normal Kubernetes pods?

You can, but each session holds a pod while it waits, which wastes CPU and memory, and starting fresh pods adds cold-start delay. Agent Substrate removes the one-agent-one-pod model, so a suspended agent doesn't hold compute and comes back with its memory intact.

What does kagent add on top of Agent Substrate?

kagent is the agent runtime and control plane. It lets you define agents declaratively as Kubernetes resources, run agents built with frameworks like LangGraph, ADK, Codex and Claude Code, manage worker pools, persist snapshots and collect telemetry. Paired with agentgateway, it also governs which tools agents can call.

How is Agent Substrate different from OpenShell?

They work at different layers. Agent Substrate decides where an agent runs and keeps it cheap and stateful, with checkpoint and restore, dense worker pools and gVisor or microVM isolation. NVIDIA OpenShell focuses on what an agent may do, with deep per-binary policy, credential handling and a strong local developer experience.

Is agent substrate the same as an agent sandbox?

No. A sandbox is an isolation technique, such as gVisor or a microVM. Agent Substrate is the layer that schedules sandboxed agents, using their snapshot and restore capabilities to move agent state between workers.

Does Agent Substrate require GKE?

No. It's portable across Kubernetes clusters. Google also offers Agent Substrate on GKE.

Is Agent Substrate production-ready?

Not yet. The open source project is pre-1.0, its security hardening is still early, authorization is experimental and GPUs are temporarily unsupported. On GKE it's available for non-production workloads, with production support by allowlist. Solo Enterprise for kagent and agentgateway add the policy, authorization and audit layers teams need on the path to production.

Go deeper on agent substrate

Webinars, guides and hands-on blogs from the team building kagent and contributing to Agent Substrate.

Webinar series

Agent Substrate 101

Three short sessions on sandboxing basics, scaling agents on Kubernetes and cutting idle agent costs.

kagent.dev blog

kagent + Agent Substrate sandboxes

How kagent runs agents on Substrate with gVisor and microVM isolation, step by step.

Solo blog

Hands-on: kagent Enterprise config

Harness, AgentTemplate and worker pools in Solo Enterprise for kagent with Agent Substrate.

Meet the Agent Substrate community at KubeCon

Join us for Agent Substrate Day, a KubeCon + CloudNativeCon North America co-located event on November 9, 2026, with talks from the people building and running it.