Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Self-hosting IBM Bob means running Bob’s backend on an OpenShift cluster that your organization manages. That gives you control over the hosting environment and, with a supported customer-installed model configuration, can keep code, development context and build artifacts within that environment. It does not automatically keep every data flow local or make a deployment compliant: model choice determines where inference happens, and your organization remains responsible for the platform controls, monitoring and processes that support its legal and contractual obligations.

What does “self-hosted” mean for IBM Bob?

Bob’s backend runs as a workload on a customer-managed Red Hat OpenShift cluster. IBM describes an installation with an operator namespace and an instance namespace. The instance namespace contains Bob application services, databases, authentication services and supporting workloads. Developers continue to use the Bob IDE extensions and BobShell; the customer takes responsibility for the backend environment and its operation.

A dedicated cluster is not required. Bob can share a cluster if it has adequate capacity, but that choice makes resource planning and the controls around shared infrastructure part of the deployment design. Self-hosting is therefore a change in operational ownership, not simply a setting that makes the service private.

Where does code and development context go?

The hosting location and the inference location are separate decisions. IBM describes both customer-installed models and supported external model services connected through approved hybrid connectivity. The model and configuration determine where inference takes place and how code and development context are processed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
IBM X3550 M4 4B Server 2X 2.50GHz E5-2640 12-Cores Total 32GB RAM ServeRAID M5110 1GB No 2.5" HDD (Renewed)
  • IBM X3550 M4 4B Server
  • 2x 2.50GHz E5-2640 12-Cores Total
  • 32GB RAM / No Hard Drives / No Hard Drive Trays
  • M5110 w/ 1GB
  • No Operating System
Configuration What IBM’s materials establish Privacy boundary to verify
Self-hosted model With a supported customer-installed model configuration, code, development context and build artifacts can remain within the customer-managed environment. Confirm which model is installed, which data Bob sends to it, and whether other service, administrative or telemetry flows leave the environment.
Air-gapped configuration IBM lists air-gapped deployment among the supported deployment choices. The specific model availability and data paths depend on the supported configuration. Verify that the intended environment is actually isolated as designed, including how software, updates, credentials and required dependencies are supplied.
Hybrid configuration Bob can connect to a supported external model service for work assigned to that service. Identify the endpoint, the data sent to it, the network and identity protections, and the provider’s applicable retention and processing terms.

IBM’s general-availability announcement on 30 September 2026 lists NVIDIA Nemotron and Poolside Laguna as self-hosted model choices, and Claude Sonnet 5.0, Claude Opus 4.8, Gemini 3.7 Flash and OpenAI GPT 5.6 Sol as hybrid/private SaaS choices. These are version-specific product details and can change; confirm current support and terms before selecting a model. A supported model list does not by itself establish that every data category, telemetry item or administrative record stays local.

For a mixed-sensitivity workflow, an organization could route less restricted work to an approved external model while reserving other work for a supported customer-installed model. That design is useful only if the routing rules, user permissions and actual data flows are understood and enforced.

What control does self-hosting give—and what work does it add?

Self-hosting gives the organization control over the infrastructure boundary and more direct influence over networking, identity, storage and the location of a customer-installed model. Those controls may help with residency or network restrictions, but the customer must configure and operate them. IBM’s materials assign customers responsibility for upgrades, scaling, availability, identity, networking and storage.

Security-event logging and monitoring are handled at the OpenShift platform level, not provided by Bob. The platform owner must configure, operate and retain logs to meet the organization’s own security, audit and compliance needs. A Bob deployment without an agreed logging and retention plan can therefore leave an important part of the control environment unaddressed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Self-hosting also shifts lifecycle planning to the enterprise: the team needs a plan for capacity as workloads grow, high availability, backup storage, platform overhead, upgrades and recovery. Those are operational requirements, not proof that any particular regulation has been met.

What infrastructure does IBM list?

IBM’s requirements page lists Bob self-hosted 2.0.0 with Bob IDE 2.2.0 and Bob Shell 2.0.5, amd64 worker nodes, and OpenShift 4.20, 4.21 or 4.22. These published requirements are version-sensitive; check the current IBM documentation during implementation planning.

Published sizing reference vCPU Memory Persistent storage
Bob Core aggregate baseline (IBM requirements page) 22.1 35.1 GiB About 30 GiB
Production reference (IBM requirements page) 28.1 41.1 GiB About 50 GiB
Headroom recommendation (IBM requirements page) Roughly 36.5 53.4 GiB Not stated on the requirements page

These are IBM’s published sizing figures, not universal hardware recommendations. Optional stacks change the footprint, and the requirements page marks some Z Understand figures provisional while benchmarking continues. Capacity planning should account for the components and workload the organization will actually deploy rather than treating the Bob Core baseline as a complete production design.

The documented dependencies include connectivity to configured LLM endpoints and container registries; LDAP or Active Directory where used; Bob ingress; and DNS and TLS validation. Persistent storage supports databases, search, cache, configuration, certificates and backups. Each dependency is also a place to verify routes, credentials, access, logging and storage behavior in the organization’s topology.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does self-hosting make IBM Bob compliant?

No deployment label can establish compliance by itself. Self-hosting can give an organization greater control over infrastructure and inference location, which may support a data-residency or security design. Whether the system satisfies a law, regulator, customer contract or internal control depends on the full configuration and the organization’s operating practices.

Before approving a deployment, map the data and control boundary end to end:

  1. Define the data in scope. Identify the code, prompts, development context, build artifacts and any other information the organization intends Bob to process.
  2. Trace processing paths. For each selected model and workflow, document where inference occurs, which endpoints receive data, and which records or supporting services may be involved.
  3. Review access and network controls. Confirm how users and services authenticate, which connections are permitted, and how the configuration enforces the organization’s intended boundary.
  4. Set logging and retention responsibilities. Decide who configures, monitors and retains platform-level security events, and how that evidence supports audit and incident response.
  5. Assess applicable obligations. Compare the actual deployment, model terms and operating procedures with the relevant legal, regulatory, contractual and internal requirements.

IBM’s product documentation describes product capabilities and operating requirements; it is not an independent security assessment, a legal interpretation or an audit of a customer’s implementation. IBM Institute for Business Value reported in 2026 that 68% of surveyed executives found meeting data-residency and sovereignty requirements across geographies challenging. That survey figure describes the broader challenge, not IBM Bob’s compliance effectiveness.

What is the practical takeaway for enterprise teams?

Choose self-hosting when the organization needs to manage Bob’s backend within its own OpenShift environment and has the platform capability to operate it. Then make a separate, explicit decision about inference location: a customer-installed model and an approved external model service create different data-processing boundaries. Treat privacy and compliance as properties of the configured system—including its access, network, model, storage, logging and operational controls—not as automatic consequences of running Bob on premises.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.