Architecture overview: IBM Sovereign Core

The IBM® Sovereign Core platform is an evolution of cloud platform design for modern applications that host AI agents and AI-powered products that operate within a sovereign boundary. The model delivers a customer-operated control plane that is built on open, enterprise-grade technologies such as Red Hat OpenShift.

IBM Sovereign Core delivers on‑demand access to shared, configurable resources. Compute, storage, and networking resources along with services, can be provisioned and released rapidly with minimal management effort through standardized service and deployment models. IBM Sovereign Core is a modern, hybrid cloud software infrastructure. For details about that standard definition, see The NIST Definition of Cloud Computing and EUCS-Cloud Services Scheme. Some key features include:
  • On-demand self-service to provision services.
  • Broad network access in air-gapped or carefully managed IBM Sovereign Core deployments.
  • Resource pooling with Kubernetes loads using abstracted, physical resources.
  • Rapid elasticity for automated provisioning and adjustments, management of resources at the cluster and service instance levels.
  • Measured services with metering, logging, and monitoring for billing and chargeback, and operational management.

Components of IBM Sovereign Core

Tenant layer - workloads and workspaces: Tenant application workloads run in workspaces in tenant worker planes. Tenant users request service offerings from the catalog, which is provisioned on demand for use in tenant workspaces. The catalog is extensible, with other service offering additions to the catalog.

Service layer - control plane and catalog management IT service provider administrators manage the control plane and services availability through the catalog, publishing catalogs to tenant users. Common services include identity and access management, secrets management, metering, and observability.

AI services layer - inferencing and agents: AI services enable in-boundary management of AI inferencing on GPUs, managed use of external models from trusted external model hosting providers, and pre-built agents. Alternatively, users can build language agents and employ IBM Sovereign Core’s AI inferencing service to power them. Similarly, AI-powered applications can use the AI inferencing service.

Governance layer - Compliance center: The Compliance center simplifies the process of identifying relevant standards and the controls related to them. Combine automated monitoring of technical controls with human-reviewed evidence and attestations to maintain an accurate, up-to-date view of compliance posture and control effectiveness.

Platform layer - cloud services and orchestration: IBM Sovereign Core provides the local cloud infrastructure, including multi-tenancy, and common services. It includes Red Hat technologies that provide aspects of cloud-native infrastructure including Kubernetes cluster management and model hosting.

Infrastructure layer - physical resources: The IT service provider supplies or contracts for the physical infrastructure resources, which are compute, storage, and networking.

Security boundary - secure landing zone: A secure landing zone provides a staging point for assets a system administrator brings into the IBM Sovereign Core high-trust zone.

Figure 1. IBM Sovereign Core architecture
IBM Sovereign Core architecture showing a layered sovereign cloud platform with physical infrastructure at the base, Kubernetes‑based cloud services, built‑in security and compliance, AI inference services, a provider‑managed control plane, and tenant workspaces for customer workloads.

System planning and requirements

IBM Sovereign Core can be deployed in one or more racks in a data center. When you are planning for a production deployment, you must plan for capacity in advance. In most deployments, the tenant worker planes use most of the system resources, and these resource demands vary significantly based on number of tenants and the amount of workloads.