Blueprint series ยท six parts

AI agents on the open stack: the six-part blueprint

Six articles that read the public code and the legal texts behind an agent platform: the stack, its vendor-free variant, what the regulations ask, how Microsoft's governance toolkit enforces it, what gets recorded, and how a model is rolled out without breaking any of that. Read in order; each part builds on the one before.

HokonokenSeptember 2026EnglishIndependent work, views are the author's own

The six articles, in reading order

PartArticleReadingLink
Part 1AI agents on OpenShift: the open blueprint, layer by layerRed Hat's July 2026 reference architecture read against the code: two exits per agent, two execution patterns, the two gaps Red Hat names itself.6 minOpen
Part 2The same agentic stack with no platform vendorEvery Red Hat box replaced by the CNCF, NVIDIA or Microsoft project it packages; what "free" means; what you take on.7 minOpen
Part 3What the regulations actually ask of an agent stackEU AI Act as amended in July 2026, NIS2, ISO 42001, Swiss FADP, FINMA 08/2024, mapped to the layer that has to answer. Not legal advice.9 minOpen
Part 4Action governance with Microsoft's Agent Governance ToolkitPolicy per action, declared intent, fail-closed approval, Merkle audit; three insertion points; the toolkit's own manifests and sector templates.11 minOpen
Part 5Observability: what the stack records, and what it cannot tell youFour records for one tool call, what an auditor asks, the six-month retention problem, why a Merkle tree needs a witness.7 minOpen
Part 6Rolling out a model blue/greenTwo llm-d pools behind one HTTPRoute, an Argo Rollouts analysis as the gate, garak probes, a person who promotes and is recorded.9 minOpen
How to read these. Every article is a reading of public code and documents at a stated date, not something run in production. Each one ends with its sources, commit hashes included, and a note asking you to test on your own cluster and to file what does not match with the project concerned.