OpenStack Hibiscus: Trusted AI Infrastructure With Confidential Compute

The News

The OpenInfra Foundation has released OpenStack 2026.2 (Hibiscus), the 34th version of its widely deployed open source cloud infrastructure platform. The release focuses on three areas: expanded confidential computing support (including AMD SEV-SNP and Intel TDX), broader infrastructure capabilities for AI and HPC workloads (adding vGPU management, Weka and Lustre parallel filesystem support, and improved bare-metal tracking), and efficiency improvements at scale (including a more than 15x reduction in HA router monitoring memory footprint). The development cycle saw approximately 600 contributors deliver 11,500 code changes, a 28% increase over the previous release, with 1.6 million automated CI jobs run through OpenDev Zuul during the cycle.

Analyst Take

The AI Infrastructure Layer Is Now a Security Competition

OpenStack Hibiscus arrives at a moment when “AI-ready infrastructure” has become a marketing phrase that means almost nothing without specifics. The Hibiscus release is specific. Hardware-backed memory encryption via AMD SEV-SNP and Intel TDX, workload attestation, tighter accelerator isolation through Cyborg, and post-quantum cryptography tooling in Designate are not checkbox features. They are direct responses to the reality that AI workloads increasingly process sensitive data at scale, often in multi-tenant environments where infrastructure-level trust boundaries matter enormously.

This is a meaningful differentiator for organizations that operate in regulated or high-security contexts. For government agencies and defense contractors in particular, the ability to run confidential compute workloads on self-controlled infrastructure, rather than relying entirely on a hyperscaler’s trust model, is worth scrutinizing closely. The data reinforces why: according to ECI Research’s Google GovTech Survey, 31.8% of respondents identified FedRAMP/compliance approval friction for AI vendors as the single largest blocker preventing widespread AI adoption in their developer workflows. A self-managed OpenStack deployment with hardware-rooted trust sidesteps that friction entirely for many workloads, because the organization controls the compliance boundary rather than waiting for a vendor’s authorization.

GPU Management Signals Where the Community Is Placing Its Bets

The expansion of mediated device support for vGPUs in Nova and Cyborg is the architectural bet that will define OpenStack’s relevance to AI practitioners over the next several years. Managing GPU resources in heterogeneous, multi-tenant environments has been a persistent gap in open source infrastructure. The Hibiscus approach, giving operators programmatic control over how accelerator resources are partitioned and provisioned, positions OpenStack as a credible alternative to proprietary GPU cloud abstractions for organizations that need to keep that layer in-house.

For developers, the practical implication is that OpenStack can now function as the orchestration substrate beneath AI training and inference clusters without requiring teams to bolt on custom tooling for accelerator management. Manila’s new support for Weka and Lustre parallel filesystems adds the high-throughput storage layer that GPU-intensive workloads actually need. These are not adjacent features. Together, they form a coherent infrastructure stack for serious AI compute, managed entirely under the operator’s control.

The deployment environment picture matters here. ECI Research’s Google GovTech Survey found that 46.9% of respondents selected “A mix of connected and disconnected (air-gapped) environments” when asked to describe their software development environments, and an additional 24.9% operate primarily in disconnected, air-gapped settings. That is nearly three-quarters of the surveyed population working in environments where commercial cloud AI infrastructure is either unavailable or architecturally inadvisable. OpenStack’s model, self-managed, hardware-agnostic, and now capable of managing accelerated compute, maps directly onto that operational reality.

Operational Efficiency Is the Quiet Win

The efficiency improvements in Hibiscus deserve more attention than they typically receive in release coverage. A 15x reduction in HA router monitoring memory footprint in Neutron is not a minor tuning change; at scale, it translates directly to the number of workloads an operator can run on existing hardware. Watcher’s improvements to workload consolidation and Glance’s parallel image import capabilities compound that effect. For operators running OpenStack across thousands of nodes, these improvements affect real budget lines. The Watcher enhancements in particular, which make consolidation responsive to both real-time usage and reserved capacity, give infrastructure teams a more precise instrument for capacity management without adding operational complexity.

Looking Ahead

The SLURP cadence question is worth watching as AI infrastructure demands accelerate. OpenStack’s model of a major upgrade every 12 months suits enterprises with stable operational rhythms, but AI workloads are evolving faster than annual cycles. The community will need to find ways to deliver accelerator support and security patches at a velocity that matches the pace of GPU hardware generations, which have historically moved on 18-to-24-month cycles but are compressing. The next SLURP release, Indri (2027.1), is the one to watch for whether OpenStack can keep pace with the next generation of AI compute hardware.

More broadly, OpenStack’s positioning in the AI era depends on whether organizations actually build and operate the kind of infrastructure that favors self-managed, open source control planes. The data suggests demand is real, but the competitive pressure from hyperscaler-managed AI infrastructure services is not diminishing. OpenStack’s long-term answer to that pressure is not feature parity with AWS or Azure; it is trust, control, and total cost of ownership in environments where those properties command a premium. Hibiscus advances that argument. Whether the market rewards it depends on how many organizations decide that sovereign infrastructure is worth the operational investment.

Authors

  • Paul Nashawaty

    Paul Nashawaty, Practice Leader and Lead Principal Analyst, specializes in application modernization across build, release and operations. With a wealth of expertise in digital transformation initiatives spanning front-end and back-end systems, he also possesses comprehensive knowledge of the underlying infrastructure ecosystem crucial for supporting modernization endeavors. With over 25 years of experience, Paul has a proven track record in implementing effective go-to-market strategies, including the identification of new market channels, the growth and cultivation of partner ecosystems, and the successful execution of strategic plans resulting in positive business outcomes for his clients.

    View all posts
  • With over 15 years of hands-on experience in operations roles across legal, financial, and technology sectors, Sam Weston brings deep expertise in the systems that power modern enterprises such as ERP, CRM, HCM, CX, and beyond. Her career has spanned the full spectrum of enterprise applications, from optimizing business processes and managing platforms to leading digital transformation initiatives.

    Sam has transitioned her expertise into the analyst arena, focusing on enterprise applications and the evolving role they play in business productivity and transformation. She provides independent insights that bridge technology capabilities with business outcomes, helping organizations and vendors alike navigate a changing enterprise software landscape.

    View all posts