live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
newsAI

Red Hat and NVIDIA put agent controls outside the agent’s reach

OpenShell and DOCA are coming to Red Hat AI Factory, while NVIDIA’s BlueField-based Sentry design adds an independent enforcement plane for agent workloads.

By The News Desk· Sep 28, 2026the quick take — two AI hosts go live when you do

NVIDIA has launched an Open Agent Safety Platform that combines an open-source runtime boundary with a hardware-isolated monitoring design, and Red Hat says it is integrating parts of that stack into Red Hat AI Factory with NVIDIA. The announcement moves agent security beyond model guardrails toward controls that the agent workload cannot directly change or bypass. (Red Hat; NVIDIA)

What changed

The platform has two main pieces. OpenShell is a broadly available secure runtime intended to trace agent actions and enforce policies while agents run. NVIDIA says the open-source software targets its Vera CPUs but can be extended to third-party compute platforms, including Arm and Intel systems. (NVIDIA)

The second piece is NVIDIA Sentry, a reference design for an out-of-band watchdog on BlueField-4 data processing units. NVIDIA says Sentry uses DOCA software to inspect requests and responses, verify agent identity, produce attested telemetry and enforce access policies for data, tools, APIs and services from an isolated trust domain. NVIDIA describes Sentry as able to quarantine an agent that crosses its boundary in milliseconds, but its release also cautions that many described products and features remain subject to availability. (NVIDIA)

Red Hat’s contribution is the enterprise platform around those controls. The company says it runs OpenShell and DOCA on Red Hat AI Factory with NVIDIA, the combined stack built from Red Hat AI, OpenShift AI, OpenShift, RHEL and NVIDIA infrastructure. Red Hat presents BlueField as an additional enforcement boundary alongside identity, authorization, workload isolation, network policy, observability and software-supply-chain controls—not as a complete answer by itself. (Red Hat; NVIDIA)

Who it affects

The immediate audience is platform and security teams preparing to let autonomous agents call enterprise APIs, use credentials, reach files and invoke tools. Red Hat’s architecture assumes those agents can behave unexpectedly and therefore treats the model as an untrusted participant rather than the primary security boundary. (Red Hat)

That design matters most for agents with meaningful authority. Runtime sandboxing can constrain processes, OpenShift can supply workload and network isolation, and a DPU-based monitor can remain outside the host environment where the agent executes. The layers address different failure modes; none replaces the others. (Red Hat)

What to do

Teams evaluating the stack should separate what is available now from the reference architecture. OpenShell is available through NVIDIA’s developer resources and GitHub, while Sentry is described as a BlueField-4 reference design. A practical evaluation should test whether policies survive a compromised or misbehaving agent, whether tool and network permissions are independently enforced, and whether audit data crosses a trust boundary the agent cannot alter. (NVIDIA)

The strategic change is the placement of control. Instead of asking only whether an agent follows instructions, Red Hat and NVIDIA are asking which identity, policy and monitoring functions must remain outside the agent’s reach. (Red Hat)

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.