Summary
- IBM Bob can run on customer-managed Red Hat OpenShift infrastructure, including on premises and in private cloud environments.
- Air-gapped deployments can use open-weight models on locally operated GPUs, while hybrid setups can call external models.
- Greater control over code, identity, and audit logs comes with greater responsibility for operating the underlying infrastructure.
IBM is allowing enterprises to run its Bob software development agent inside infrastructure they control, extending the product into environments where proprietary source code, regulated information, or network policy make a conventional public AI service difficult to use.
IBM announced the self-hosted option on 1 October after Bob became generally available in September. The backend runs on Red Hat OpenShift clusters operated by the customer, either on premises or within its own cloud account, while developers continue using the same development environment and command line tooling.
The underlying model can vary with the deployment. An organisation may connect Bob to an external frontier model through a cloud service or operate an open-weight model on its own GPUs where an air-gapped environment is required.
That architecture gives banks, public bodies, healthcare organisations, industrial companies, and other regulated operators more control over where source code and application context travel. Software development agents need substantially more access than conventional code completion tools when they inspect repositories, alter several files, run tests, or interact with other development systems.
Source code creates a different data problem
A repository can contain intellectual property, undocumented business logic, internal architecture, security weaknesses, or credentials accidentally committed by developers. Giving an agent broad access can expose far more organisational information than asking a general AI service to draft text or summarise a public document.
IBM’s self-hosted package includes identity functions, an inference gateway, audit logging, and usage metering, with installation managed through an OpenShift operator. Bob runs as a namespaced workload and can share a cluster with other applications rather than requiring a dedicated infrastructure estate.
Developers connect to an internal endpoint, allowing organisations to move the backend without creating an entirely separate user experience. That can simplify adoption in businesses already standardised on OpenShift while keeping network and identity controls closer to existing enterprise infrastructure.
IBM describes sovereignty as one reason for the design, although deployment on customer infrastructure does not make every configuration sovereign in the same sense. A locally hosted Bob instance that calls an external frontier model still depends on the provider of that model and the contractual and geographic conditions surrounding the service.
An air-gapped deployment with an open-weight model removes more external dependencies but transfers additional operational responsibility to the customer. Hardware capacity, model serving, patching, performance, and upgrades all have to be managed somewhere, so greater control arrives with greater infrastructure work.
AI coding tools are becoming part of software governance
Early generative coding products could often be assessed primarily as developer tools, with procurement focused on licence cost and individual productivity. Agentic systems reach further into repositories, test environments, modernisation projects, and toolchains, bringing them closer to identity, supply chain security, and change control.
Organisations still need to decide which repositories Bob can inspect, which tools it can invoke, how generated changes are reviewed, and whether an automated workflow can alter dependencies or security-sensitive code. Audit logs can reconstruct activity, but they do not determine whether a change was technically sound.
Red Hat OpenShift also anchors the product firmly inside IBM’s hybrid cloud strategy. Existing OpenShift customers gain a familiar deployment layer, while IBM gets a way to differentiate Bob from agents designed principally around a vendor-operated public service.
The trade-off is operational. IBM says the hosted version remains appropriate for teams that want the vendor to handle backend updates and infrastructure. Self hosting becomes more attractive when data location, network separation, security, or regulation outweigh the convenience of that managed service.
The distinction will become more important as coding agents acquire background processes and broader connections to developer tooling. A system that can inspect a repository and act across several development steps needs to be governed more like infrastructure than a simple assistant.
For enterprises comparing AI development products, model quality will sit alongside repository access, network boundaries, auditability, model choice, operational ownership, and data location. Bob’s new architecture gives customers more control over those choices without pretending that control is free of cost.












