MAQPNA

Compare

Self-hosted vs hyperscaler agent runtimes.

The large cloud providers now offer managed runtimes for AI agents, for example AWS Bedrock AgentCore, Azure AI Foundry Agent Service and Google Vertex AI Agent Engine. They are a good choice for many teams. This guide explains when running your own runtime is the better fit.

In short

  • Managed runtimes remove operations work and integrate tightly with one provider's models, identity and monitoring.
  • A self-hosted runtime runs where you choose, including on-premises and air-gapped, under your keys and your jurisdiction, and moves with you between clouds.
  • The deciding questions are sovereignty, portability and who must be able to operate and inspect the platform.

Side by side

Hyperscaler-managed runtimeSelf-hosted runtime (MAQPNA)
Where agents runIn the provider's cloud, in the regions it offersOn any conformant Kubernetes: on-premises, any cloud, sovereign clouds, air-gapped sites
Control planeOperated by the providerRuns in your cluster; no vendor control plane
JurisdictionThe provider's terms and the laws that apply to the providerWherever you run it, pinned by a sovereignty policy
KeysProvider key services, with customer-managed key options that vary by providerYour file store, PKCS#11 HSM or KMS
Outbound callsPart of the managed serviceNone by default: no telemetry, no licence server
PortabilityBuilt around one provider's APIs and servicesKubernetes, MCP, A2A, OIDC and OpenTelemetry; any model through OpenAI-compatible routes
OperationsManaged for youYou or a service provider run it, with Helm and the maqpna CLI
BillingUsage-based, on your cloud billCommunity is free; commercial editions by agreement; compute is yours

Managed services change quickly. Check each provider's current documentation for regions, features and key-management options.

Choose a managed runtime when

  • Your workloads already live in one cloud and will stay there
  • The provider's regions meet your residency needs
  • You have no platform team to run Kubernetes
  • You want the provider's models and tools with the least integration work

Choose a self-hosted runtime when

  • Data or operations must stay in your jurisdiction, on-premises or air-gapped
  • You must hold the keys and be able to inspect everything that runs
  • You run on more than one cloud, or want to keep the option
  • You host agents for your own customers, as a data centre or cloud provider

FAQ

Common questions

Can MAQPNA run on a hyperscaler's Kubernetes?

Yes. There are install guides for Azure AKS, Amazon EKS, Google GKE and OpenShift. You keep the portability and sovereignty controls, and run where your cloud contract already is.

Can agents still use a provider's models?

Yes, if your policy allows it. Model calls go through the gateway's model routes, with allow-lists per agent and residency checks, to any OpenAI-compatible endpoint.

Who operates MAQPNA if we have no platform team?

A service provider can. The Operator edition lets data centres and clouds host governed agents for their customers, in their region.

Keep agents on infrastructure you control.

Try MAQPNA locally, or talk to us about running it on your clusters, on-prem or in a sovereign cloud.

curl -fsSL https://maqpna.com/install.sh | sh

No Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.