Agent Substrate + kagent
Run stateful AI agents on Kubernetes without a pod per agent.
AI agents spend most of their lives waiting. Agent Substrate is the open source runtime that checkpoints an agent, memory and filesystem included, and restores it on any free worker, so a small pool of pre-warmed pods can serve many isolated agent sessions. kagent turns it into a platform your teams can actually use.
Why agent substrate
Kubernetes was built for services that stay busy. Agents don't.
Agent Substrate is a runtime and scheduler that sits on Kubernetes and matches how agents actually behave: bursty, stateful and idle most of the time. It decides where each agent runs and keeps it cheap to hold.
Agents are idle most of the time
An agent fires a model call or a tool call, then waits on a person, an API or another agent. With a pod or sandbox per agent, each session holds its CPU and memory for its whole life, whether it's working or not.
Scaling pods is too slow for agents
Spinning up a fresh pod per session adds cold-start delay users can feel, and thousands of short-lived pods put real pressure on the control plane.
Agents need memory that survives
A restarted container loses what the agent had in memory. Agents need their full state saved and restored, not just a disk volume, so a session can pick up exactly where it left off.
~250
stateful actors on 8 pods in the project's reference demo
1,000
actors per worker by default
3
checkpoint modes: suspend, pause and revert
2
sandbox types: gVisor and microVMs
From the open source project's defaults and reference demo. The project is pre-1.0.
How it works
Many actors. A few warm workers. State that follows the agent.
Agent Substrate treats each agent session as an actor and keeps a small pool of ready workers. When an actor is called, its saved state is restored onto a free worker. When it's suspended, its memory and filesystem changes are checkpointed to object storage and the worker moves on. New actors start from a golden snapshot of their template instead of cold-booting.
Agent Substrate with kagent
Substrate schedules agents. kagent makes them a platform.
Agent Substrate is a low-level runtime: actors, workers and APIs. kagent is the open source, Kubernetes-native layer on top that gives developers a way to build and ship agents, and gives platform teams a way to run them.
Declarative agents as Kubernetes resources
Define agents with kagent's Harness and AgentTemplate resources and ship them with GitOps, the same way you ship everything else. kagent handles the Substrate APIs.
Bring the framework you already use
Run agents built with LangGraph, Google ADK, Codex or Claude Code on Substrate, from the kagent UI or from code.
Worker pools that scale themselves
kagent manages Substrate worker pools across your nodes and scales them with demand, so platform teams don't hand-tune capacity.
Snapshots you can keep and fork
Substrate can tag snapshots and clone them into another tenant, so you can fork an agent from a known state. kagent snapshot policies put that to work, and Solo Enterprise for kagent adds context snapshots for reproducible debugging.
L7 policy, authorization and audit through agentgateway
Substrate's own egress controls match on hostname and port. agentgateway, already a routing option in Substrate's network layer, adds MCP- and A2A-aware policy, authentication and audit on top.
Observability built in
OpenTelemetry tracing and metrics, plus a Substrate dashboard in Solo Enterprise for kagent that shows which actors are running or idle.
Agent Substrate vs. OpenShell
Different layers, different strengths
Agent Substrate and NVIDIA OpenShell both isolate agents, so they get compared a lot. Substrate is the runtime underneath: it decides where an agent runs and keeps it cheap and stateful. OpenShell is strongest above that, controlling what an agent may do. Here's an honest look at both.
| Agent Substrate where an agent runs | NVIDIA OpenShell what an agent may do | |
|---|---|---|
| Agent state | Checkpoints memory, filesystem changes and durable directories to GCS or S3, then restores on any free worker. Suspend, pause and revert. | A restart doesn't restore process memory. On Kubernetes, stopping a sandbox deletes the pod and keeps its disk volume. |
| Density | Many actors share a pool of pre-warmed workers, up to 1,000 per worker by default, autoscaled with HPA. | One sandbox per agent for its whole life; two pods per sandbox on Kubernetes. |
| Fork from a known state | Golden snapshot per template; tagged snapshots can be cloned into another tenant. | No equivalent. |
| Isolation boundary | gVisor by default, or microVMs. | Landlock and seccomp on the shared host kernel, or a libkrun VM. |
| Kubernetes control plane | Own CRDs and gRPC scheduler; per-actor state kept out of etcd. | A driver on the SIG agent-sandbox CRD; each sandbox is a Kubernetes object. |
| Policy depth | Egress matched on hostname and port. | Per-binary OPA/Rego rules that understand REST, MCP, GraphQL and more, with formal verification of changes. |
| Credentials and audit | Placeholder secrets swapped at the proxy; authorization is experimental. | Adds SigV4 re-signing, OAuth token exchange, Vault and OCSF audit logs. |
| Developer experience | Kubernetes only; Go APIs. | One-line local install on Docker, Podman or macOS; Python, TypeScript and Go SDKs. |
| GPUs | Temporarily unsupported. | Supported. |
| Project governance | Open source, maintainers from Google and Solo.io, intended for CNCF. | Open source, led by NVIDIA. |
Highlighted cells show where each project is further along, based on each project's public code and docs as of October 2026. Agent Substrate's published performance figures are project targets; benchmark results haven't been published yet.
Agent Substrate
The runtime underneath
Substrate decides where an agent runs and keeps it cheap and stateful: checkpoint and restore, dense worker pools, forking and a strong isolation boundary.
OpenShell
Strong above that layer
OpenShell's strengths are in controlling what an agent may do: deep policy, credential handling, audit and an easy local developer setup.
kagent + agentgateway
Closing the gap on Substrate
Substrate's thinnest areas are L7 policy, authorization and audit. agentgateway is already a routing option in Substrate's network layer, and kagent makes Substrate usable day to day.
FAQ
Agent substrate questions, answered
The short answers to what teams ask most about Agent Substrate, kagent and sandboxing.
What is agent substrate?
Agent Substrate is an open source runtime and scheduler for running AI agents on Kubernetes. It maps many mostly idle agent sessions (actors) onto a smaller pool of pre-warmed pods (workers), checkpointing an agent's memory and filesystem to object storage and restoring it on any free worker.
Why can't I just run agents as normal Kubernetes pods?
You can, but each session holds a pod while it waits, which wastes CPU and memory, and starting fresh pods adds cold-start delay. Agent Substrate removes the one-agent-one-pod model, so a suspended agent doesn't hold compute and comes back with its memory intact.
What does kagent add on top of Agent Substrate?
kagent is the agent runtime and control plane. It lets you define agents declaratively as Kubernetes resources, run agents built with frameworks like LangGraph, ADK, Codex and Claude Code, manage worker pools, persist snapshots and collect telemetry. Paired with agentgateway, it also governs which tools agents can call.
How is Agent Substrate different from OpenShell?
They work at different layers. Agent Substrate decides where an agent runs and keeps it cheap and stateful, with checkpoint and restore, dense worker pools and gVisor or microVM isolation. NVIDIA OpenShell focuses on what an agent may do, with deep per-binary policy, credential handling and a strong local developer experience.
Is agent substrate the same as an agent sandbox?
No. A sandbox is an isolation technique, such as gVisor or a microVM. Agent Substrate is the layer that schedules sandboxed agents, using their snapshot and restore capabilities to move agent state between workers.
Does Agent Substrate require GKE?
No. It's portable across Kubernetes clusters. Google also offers Agent Substrate on GKE.
Is Agent Substrate production-ready?
Not yet. The open source project is pre-1.0, its security hardening is still early, authorization is experimental and GPUs are temporarily unsupported. On GKE it's available for non-production workloads, with production support by allowlist. Solo Enterprise for kagent and agentgateway add the policy, authorization and audit layers teams need on the path to production.
Go deeper on agent substrate
Webinars, guides and hands-on blogs from the team building kagent and contributing to Agent Substrate.
Webinar series
Agent Substrate 101
Three short sessions on sandboxing basics, scaling agents on Kubernetes and cutting idle agent costs.
kagent.dev blog
kagent + Agent Substrate sandboxes
How kagent runs agents on Substrate with gVisor and microVM isolation, step by step.
Solo blog
Hands-on: kagent Enterprise config
Harness, AgentTemplate and worker pools in Solo Enterprise for kagent with Agent Substrate.
Meet the Agent Substrate community at KubeCon
Join us for Agent Substrate Day, a KubeCon + CloudNativeCon North America co-located event on November 9, 2026, with talks from the people building and running it.