Live
Linux Patch Management Remains a Bottleneck as AI Security Tools EmergeDesigning a Targeted SRE Journey at KubeCon 2026Unified AI Observability: What Dynatrace’s Acquisition of Arize Means for Full‑Stack MonitoringDocker Cloud Sandboxes provide microVM isolation for agent workloadsSecure Multi‑Environment Access for Claude Platform Using a Dedicated AI Services AccountVS Code September 2026: Copilot Agent Controls and Automation Features for Faster Merge CyclesGPU‑Accelerated Inference with GPT‑6 Astra Ultrafast: What Engineers Need to KnowSelf‑Hosted AI Coding Agent: IBM Bob Now Operates Inside the FirewallLinux Patch Management Remains a Bottleneck as AI Security Tools EmergeDesigning a Targeted SRE Journey at KubeCon 2026Unified AI Observability: What Dynatrace’s Acquisition of Arize Means for Full‑Stack MonitoringDocker Cloud Sandboxes provide microVM isolation for agent workloadsSecure Multi‑Environment Access for Claude Platform Using a Dedicated AI Services AccountVS Code September 2026: Copilot Agent Controls and Automation Features for Faster Merge CyclesGPU‑Accelerated Inference with GPT‑6 Astra Ultrafast: What Engineers Need to KnowSelf‑Hosted AI Coding Agent: IBM Bob Now Operates Inside the Firewall
Anthropic

Self‑Hosted AI Coding Agent: IBM Bob Now Operates Inside the Firewall

AI SummaryPowered by AI

IBM announced that its Bob agentic software development platform is now generally available as a self‑hosted offering that can run on‑premises, in private or sovereign clouds, and even in air‑gapped environments. This change lets AI, cloud, DevOps, and security teams place the coding agent where their code and data reside, shifting operational and governance responsibilities onto the organization.

IBM has moved its Bob agentic software development platform from a SaaS‑only model to a self‑hosted deployment that can run on‑premises, in private or sovereign clouds, and in fully air‑gapped environments. For engineers who must keep source code and sensitive data inside controlled zones, the shift means the same AI‑driven coding assistant can be used without sending artifacts to an external public cloud.

Deployment Options and Architecture

Bob now supports four distinct footprints:

  • On‑premises data centers
  • Private cloud installations
  • Sovereign cloud environments that satisfy regional residency rules
  • Air‑gapped sites with no external network connectivity

In each case the platform can host licensed models locally, including IBM Granite and open‑source options such as Mistral, while still being able to route specific tasks to external services like Anthropic’s Claude when a hybrid configuration is chosen. The architecture retains Bob’s internal coordination layer that orchestrates specialized agents for code generation, test creation, documentation, and pipeline integration.

Operational Implications

Running Bob inside an organization’s own infrastructure transfers several operational responsibilities to the platform team:

  • Provisioning and maintaining GPU capacity for the hosted models.
  • Applying model updates and patches on a schedule that aligns with change‑management policies.
  • Monitoring agent behavior for drift, performance regressions, or unexpected output.
  • Maintaining audit trails that satisfy regulator‑driven traceability requirements.

Hybrid deployments allow a subset of tasks to call out to external model services, but they also require network segmentation and policy enforcement to keep the outbound traffic within approved boundaries.

Security and Governance Considerations

Bob includes built‑in approval checkpoints, sensitive‑data scanning, and real‑time policy enforcement. Those controls remain necessary after the move to self‑hosting, but they must now be integrated with the organization’s existing CI/CD gate‑keeping, change‑approval, and secret‑management processes. Air‑gapped installations limit the catalog of available models, so teams need to evaluate whether locally hosted models meet the quality expectations for their use cases.

Neel Sundaresan, IBM’s general manager of AI and automation, emphasizes that the offering is intended to “bring AI to the data instead of moving the data for the AI.” Mitch Ashley of The Futurum Group notes that a trusted, firewall‑resident agent can become a platform for building additional internal agents, turning the initial adoption into a multi‑year commitment.

Related CloudNinjas coverage: AI engineering.

What This Means For Practitioners

Practitioners should start by mapping the parts of their software development lifecycle that would benefit from an AI coding assistant and cross‑referencing those touch points with data‑residency, network‑segmentation, and CI/CD policies. The next steps are to:

  1. Validate that the required models can be hosted on the available hardware and meet performance expectations.
  2. Define the approval‑checkpoint workflow and policy rules that will govern agent actions within existing change‑management frameworks.
  3. Plan for ongoing operational tasks such as GPU provisioning, model versioning, and audit‑log retention.
  4. Consider a hybrid approach if certain high‑value tasks need external model capabilities while keeping core code and data on‑prem.

By addressing these items early, teams can leverage Bob’s capabilities without exposing regulated code to external clouds, while also preparing for the added operational overhead that self‑hosting entails.

Originally published atDevOps.com