World's Fair 2025
Building agent fleet architectures your CISO doesn't hate — Lou Bichard, Gitpod
Overview
This talk discusses the evolution of Gitpod's architecture to support secure development environments, particularly for regulated industries, and how this foundation enables a privacy-first AI agent offering. The core thesis is that simplifying infrastructure, moving away from complex systems like Kubernetes towards native cloud services, leads to better security, lower operational overhead for customers, and a more robust platform for deploying advanced tools like AI agents.
Who should watch
- AI engineers and builders exploring secure agent architectures.
- Product Managers and engineers focused on shipping AI tools in enterprise environments.
- Developers and IT professionals evaluating AI tools for regulated industries.
- Vendors seeking to build simplified, customer-friendly technical architectures.
- Anyone concerned with the security and operational implications of AI tool deployment.
Key takeaways
- Gitpod transitioned from a managed SaaS product on Kubernetes to self-hosted, then a managed AWS-based substrate, before finally moving away from Kubernetes entirely for its core infrastructure.
- Kubernetes presented significant complexity and operational overhead, making it unsuitable for Gitpod's goal of providing secure, easy-to-manage development environments for regulated industries.
- The current architecture utilizes native cloud services like AWS ECS and EC2, running a simple containerized runner on customer infrastructure to handle secure workloads like source code.
- This simplified, API-first architecture allows Gitpod to offer a privacy-first AI agent solution that runs within the customer's environment, inheriting the same security and access controls as human developers.
- Key considerations for adopting AI tools include understanding their underlying architecture and infrastructure, especially regarding data security and operational burden.
- Vendors can benefit from simplifying their technical architecture to reduce customer overhead and improve product adoption.
- The agent offering leverages the existing secure dev environment infrastructure, providing agents with necessary access to source code and internal systems.
- An API-first approach ensures all interactions are audit-logged, extending this benefit to agent tasks for enhanced transparency.
Notable quotes
*The core workload that we spin up is then dev environments.*
*We decided to move away from that and start to think from first principles about what an architecture looks like that solves this challenge of running inside of regulated companies.*
*When you're then ultimately looking at if you're purchasing other tools, AI tools, these are the types of considerations you want to make about what is the architecture and infrastructure.*
Unofficial community note. Prefer the recording for nuance.