Agent Substrate is now available on Google Kubernetes Engine as an open-source, secure-by-default execution runtime designed to run millions of AI agent sandboxes with 10x higher density than standard containers and sub-500ms resume operations. It addresses core challenges in scaling agent platforms—such as opaque trust boundaries, tool access friction, massive bursts, and idle compute waste—by decoupling execution from machine management using hardware-isolated microVMs or gVisor sandboxes, a dedicated control and data plane for low-latency activation, and Kubernetes for infrastructure resilience. Built for agentic workloads, it enables zero-idle compute economics by snapshotting and resuming agent states in milliseconds, freeing resources during dormancy while preserving state. Early adopters like Nous Research are using it to power Hermes, the #1 AI agent globally by OpenRouter usage. Agent Substrate runs on any Kubernetes cluster but is optimized for GKE with support for custom ComputeClasses, Google Axion Arm processors, and optional Filestore agent volumes for near-instant NFS workspace attachment. GA for production is available via allowlist, with documentation and source code accessible via the official GKE AI/ML install guide and ate.dev.


Security and performance foundations
Agent Substrate enforces security by default at both the kernel and network layers, using hardware-isolated Cloud Hypervisor microVMs or gVisor sandboxes to prevent host escape and credential theft from untrusted agent-generated code. An integrated gateway manages all egress and ingress traffic, applying granular network policies and injecting credentials outside the agent’s reach to eliminate exfiltration risks.
The runtime achieves sub-500ms resume operations and supports over 500 suspend/resume activations per second by running on pre-warmed workers and avoiding container boot delays. Snapshots of agent state are written to local disk and Google Cloud Storage, enabling durable persistence and rapid restoration when agents become active again after waiting on model inference or tool responses.
This activation model allows Agent Substrate to suspend idle agents in hundreds of milliseconds, freeing CPU and RAM for other workloads. Unlike traditional containers that reserve resources regardless of activity, Agent Substrate implements an active-only compute model that dramatically improves efficiency for agent fleets spending most of their time dormant.
Architecture and integration with Kubernetes
Agent Substrate splits responsibilities between a dedicated control plane for data-aware scheduling and a data plane that handles high-frequency suspend/resume operations directly on local workers. This separation reduces latency by bypassing the standard Kubernetes Pod lifecycle for agent execution while still relying on Kubernetes for node self-healing, autoscaling, multi-zone scheduling, and cluster reliability.
Worker pods managed by Kubernetes run the Agent Substrate data plane, allowing standard Pod semantics to coexist with agent-native execution. Existing primitives like Agent Sandbox and kernel-isolated Pods continue to function side by side, ensuring compatibility with current tooling and workflows that require conventional container behavior.
By combining low-latency agent execution with Kubernetes’ operational resilience, Agent Substrate avoids the trade-off between control and scalability. Platform teams gain isolation and performance without sacrificing the self-healing, declarative management, and fleet-wide automation that Kubernetes provides at the infrastructure layer.
Optimized for Google Cloud and production readiness
On GKE, Agent Substrate leverages custom ComputeClasses to dynamically manage machine pools across shapes and families, including spot and on-demand instances, and supports Google Axion Arm-based processors, which deliver up to 30% better price-performance for sandbox workloads compared to alternatives. For stateful agent workspaces, optional Filestore agent volumes attach and detach NFS mounts in milliseconds, enabling near-instant workspace resumption with RWX access and POSIX-compliant file locking for safe multi-agent collaboration.
Nous Research, creators of the Hermes Agent—the #1 AI agent globally by OpenRouter usage across productivity, coding, CLI, and personal agents—has been an early design partner, validating Agent Substrate’s ability to meet isolation and identity requirements at scale. Their feedback confirms the platform preserves compute resources while enabling extensible access control and per-agent isolation in enterprise deployments.
Agent Substrate is open source and available to all GKE customers for non-production workloads. General availability for production use is offered via allowlist, with deployment guidance in the Agent Substrate on GKE documentation and source code accessible at ate.dev. Teams can begin evaluating the runtime today to build agent platforms that scale without compromising security, latency, or efficiency.
What to do next
To get started, review the Agent Substrate on GKE documentation for installation steps and configuration options. Experiment with non-production workloads to validate performance and security characteristics in your environment. For production planning, engage with your Google Cloud representative to discuss allowlist access. Combine Agent Substrate with Filestore agent volumes if your agents require persistent, shared workspaces. Monitor resource utilization to validate the zero-idle compute model in action.
Source: Agent Substrate brings high-density, scalable, trusted infrastructure to GKE (GCP).



