Teleport Launches Beams, Trusted Agent Runtimes For Infrastructure

Teleport today announced Beams, a trusted runtime designed to solve the security and IAM challenges blocking teams from designing and running AI agents in production infrastructure. Beams runs each agent in an isolated Firecracker VM with built-in identity. Each Beam is connected to infrastructure and inference services without secrets, with audit and access control.

Beams addresses a key challenge engineers face when designing agentic workflows for infrastructure. Engineers want to develop, test and deploy agents, but they need to do this in a secure environment. Today, launching agents means stitching together IAM, infrastructure, and secrets by hand — with no consistent identity, no visibility into agent actions, and every team building its own container or VM workflows from scratch. Beams eliminates that operational drag by providing ephemeral, isolated environments that are fast to start, locked down, and wired into Teleport’s identity and audit trails.

Each Beam runs in a Firecracker VM with full file system and networking isolation. Beams inherit delegated identity so they can authenticate to registered services and inference endpoints without using secrets, with fine-grained networking control over external and internal services. Every action is audited, giving teams full visibility into what agents access and when.

Beams are built for a range of agentic use cases — from internal agents that need access to production services, to agentic ephemeral workflows where developers build against staging without exposing secrets, to multi-agent production pipelines requiring hardened, reproducible isolation.Beams will launch as an MVP on April 30, 2026. Engineers interested in early access can register at https://www.beams.run.

Teleport will demonstrate Beams at both RSAC (Booth S-3111) and KubeCon (Booth 840) during the week of March 23.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading