Google Cloud announced Agent Substrate availability on Google Kubernetes Engine on September 15. The open-source runtime is designed to run high-density agent sandboxes, with isolation and suspend-resume features intended for workloads that create many short-lived or stateful environments.
Agents that can execute code or interact with tools need boundaries around files, credentials, network access and compute. A substrate built on Kubernetes could make those environments easier to provision at scale, though the security of any deployment still depends on configuration and threat modeling.
Infrastructure for agentic software
The move reflects a shift from serving model requests to hosting entire agent sessions. Each session may need a workspace, dependencies and a safe place to run actions. Efficiently suspending and restoring that state could reduce resource waste while keeping the interaction responsive.
Isolation needs careful review
An open-source runtime is not a security guarantee on its own. Operators should inspect the project’s isolation model, patching practices, permissions and network controls, then test whether boundaries hold under realistic workloads before trusting it with sensitive tasks.

