IBM Bob becomes self‑hosted on OpenShift, supporting fully air‑gapped coding‑agent deployments
IBM announced that its Bob agentic development platform is generally available for self‑hosted deployment on Red Hat OpenShift, with options for air‑gapped installations, private model connectivity and new streaming transport.

On 24 September 2026 IBM said its Bob agentic development platform reached general availability as a self‑hosted solution. The announcement marks the first time the platform can be run inside a customer’s own Red Hat OpenShift cluster, rather than as a cloud‑only service. IBM positions the move as a response to enterprises that need tighter control over data, model licensing and network exposure while still wanting to leverage large‑language‑model‑driven coding assistance.
What IBM Bob is and the shift to self‑hosted
Bob is marketed by IBM as an “agentic development platform,” meaning it embeds generative‑AI agents directly into the software‑development workflow. These agents can suggest code, refactor snippets, and answer technical questions in real time. By moving from a purely SaaS offering to a self‑hosted model, IBM aims to give organizations the ability to keep all prompts, responses and audit trails inside their own security perimeter. The platform’s core claims include built‑in identity management, an inference gateway that routes requests to selected models, comprehensive audit logging and usage metering that can be tied to internal charge‑back systems.
Running Bob on Red Hat OpenShift
In the self‑hosted configuration Bob runs as a namespaced workload inside an organization’s OpenShift cluster. Each deployment lives in its own Kubernetes namespace, isolating resources from other workloads while still sharing the underlying cluster infrastructure. The workload bundles four primary services: an identity component that authenticates users against corporate directories, an inference gateway that forwards prompts to the chosen model provider, an audit‑logging service that records every request and response, and a usage‑metering service that aggregates token consumption for reporting. IBM notes that the installer, called bobctl, separates cluster‑wide administrator tasks—such as creating the namespace and configuring role‑based access—from the per‑namespace installation steps, simplifying governance for large IT teams.
Model connectivity and air‑gapped deployment
Customers can link Bob to approved frontier models through their own cloud accounts on AWS Bedrock, Azure OpenAI, Google Vertex AI or any OpenAI‑compatible endpoint. For organizations that require a completely isolated stack, IBM also supports running open‑weight models on on‑prem GPUs. The company specifically calls out NVIDIA’s Nemotron 3 Ultra and the Poolside Laguna S 2.1 as supported for the fully isolated route, allowing inference to stay inside the data centre. The bobctl installer can mirror all container images to a private registry, a prerequisite for air‑gapped networks that have no internet access. Corporate identity integration works with LDAP or Active Directory, letting existing user groups inherit Bob permissions without additional credential stores. Together, these features enable a deployment that never touches the public internet while still giving developers access to the latest large‑language models.
Transport updates and extensibility
The September release also drops the legacy HTTP + SSE MCP transport in favor of newer Streamable HTTP variants, which IBM says improve latency and reliability for high‑throughput coding sessions. Background processes have been added to handle model warm‑up and cache management without blocking user requests. Finally, Bob now supports plugin directories, allowing third‑party extensions to be dropped into a designated folder and automatically discovered at runtime. This extensibility point is intended to let enterprises add custom linters, security scanners or domain‑specific knowledge bases without modifying the core platform.
- Namespaced workload on Red Hat OpenShift with isolated resources
- Identity integration via LDAP or Active Directory
- Support for cloud‑hosted frontier models and on‑prem GPU inference (NVIDIA Nemotron 3 Ultra, Poolside Laguna S 2.1)
- bobctl installer with private‑registry mirroring for air‑gapped environments
- Streamable HTTP transport, background processes and plugin directory extensibility
For organizations in the United States and elsewhere, the new self‑hosted option means they can now run IBM Bob inside their own security boundaries, connect it to whichever model provider they already trust, and even keep the entire stack offline if required. The shift eliminates the need to send proprietary code snippets to external SaaS endpoints, while still delivering the productivity gains promised by generative‑AI coding assistants. Enterprises that have already invested in Red Hat OpenShift or on‑prem GPU clusters can therefore adopt Bob without additional infrastructure, and they gain immediate access to IBM’s audit and metering capabilities for compliance reporting.
Sources
- Run Bob on your own infrastructureIBM Bob · October 1, 2026
- IBM Brings Bob to Self-Hosted and Air-Gapped EnvironmentsMarkTechPost · October 3, 2026



