Kubermatic branding element
Business Case

BWI GmbH, the German Bundeswehr’s primary IT and digitalization partner, is building the infrastructure needed to bring AI into defence operations and research.

As demand for AI grows, BWI needs to provide GPU infrastructure across central datacenters, edge locations, and disconnected field environments. The challenge was how to make that infrastructure available quickly and securely.

Traditionally, getting access to GPU resources meant individual requests, approvals, procurement, hardware delivery, and manual setup. Teams could wait months before they had the infrastructure they needed. At the same time, BWI needed multiple teams to share expensive GPU hardware without giving them access to each other’s workloads or data. The infrastructure also had to remain sovereign and operate in environments without a permanent connection to a central datacenter.

To address this, BWI worked with SVA and Kubermatic to build xPlatforms (BwXLab): a self-service platform for running GPU-powered AI workloads across BWI’s infrastructure. SVA brought its understanding of BWI’s environment and requirements, and Kubermatic brought the Kubernetes and cloud-native expertise needed to design and build the platform on Kubermatic AI. The resulting platform combines four key components:

  • Kubermatic Kubernetes Platform (KKP) for multi-tenant, multi-cluster Kubernetes management, with the NVIDIA GPU Operator integrated by default.
  • Kubermatic Virtualization, built on KubeVirt, for GPU access: physical GPUs can be time-sliced across multiple teams for shared workloads, or passed through directly for workloads that need a full GPU.
  • KubeLB for load balancing across the cluster fleet, including sites that need to keep operating without a live connection back to the core datacenter.
  • Kubermatic Developer Platform (KDP), the self-service catalog layer being rolled out on top of the platform. Teams pick the resources and node types they need from the catalog and get one of KKP’s cluster templates provisioned for them, rather than requesting a cluster manually. BWI is in the process of moving onto KDP from its earlier, CRD-based provisioning approach.

Together, these four components give BWI a shared GPU infrastructure platform: multiple teams can use the same hardware while keeping their workloads and data isolated, and GPUs can be shared across workloads instead of requiring dedicated hardware for every project. Different AI workloads, from LLM inference and computer vision to image generation and GPU-powered training, can run side by side on the same infrastructure, without requiring separate hardware and procurement processes for every project.

BWI offices
BWI offices

Most importantly, the process has changed from months to minutes. Instead of waiting for a new procurement cycle and manually building infrastructure, teams can request what they need and have their environment provisioned through self-service.

The platform is also designed for the realities of defence environments. The same architecture can run in BWI’s central datacenters and at disconnected field sites, allowing AI capabilities to be deployed where they are needed without relying on continuous connectivity to a central environment.

And because the platform runs on BWI-owned infrastructure and is built on open-source Kubernetes and virtualization technology, BWI retains control over its infrastructure and data rather than depending on a proprietary cloud or virtualization stack.

What used to mean a procurement cycle, getting budget approved, buying hardware, and waiting for delivery, now takes minutes through self-service. The same architecture that runs BWI’s core datacenters is also deployed at a disconnected field site, giving BWI one consistent way to run AI infrastructure whether it’s in the datacenter or in the field.

xPlatforms is one of the first sovereign, self-service GPU infrastructure platforms built specifically for a European defence organization, and it gives BWI a way to keep up with AI infrastructure demand without giving up control over its own infrastructure or data.

Frequently Asked Questions

What is a sovereign AI platform, and why does it matter for defence organizations?

A sovereign AI platform runs entirely on infrastructure the organization owns and operates, with no dependency on foreign cloud providers, and is built on open-source technology rather than one vendor’s proprietary stack. It matters for defence organizations because AI workloads often involve sensitive data that can’t leave the organization’s own infrastructure. Kubermatic AI is built this way end to end, on Kubermatic’s own open-source Kubernetes and virtualization stack, which is what BWI runs its platform on.

Why does getting access to GPU infrastructure take so long?

GPU resources are often locked behind infrastructure requests, manual setup, and separate environments for each team or project. Kubermatic AI turns existing GPU infrastructure into a self-service platform, so teams can quickly access the GPU resources and AI services they need — while platform teams maintain centralized control and improve utilization.

At BWI, Kubermatic enabled teams to get fully configured GPU environments in minutes instead of waiting months.

Can multiple teams share GPU infrastructure without compromising security?

Yes. Pooling GPUs at the infrastructure layer doesn’t require pooling access. Kubermatic Virtualization can time-slice a physical GPU across several teams, or pass it through directly for workloads that need a dedicated GPU, while Kubermatic Kubernetes Platform (KKP) keeps each team’s workloads and data isolated at the cluster level. This is how Kubermatic lets multiple BWI units draw from the same GPU pool without reaching into each other’s environments.

What is GPU time-slicing, and how does it lower infrastructure costs?

GPU time-slicing lets several workloads share one physical GPU instead of each needing its own, so organizations get more out of the hardware they already own instead of buying more. Kubermatic Virtualization is what makes this possible at BWI, letting the platform run LLM inference, computer vision, and training notebooks from the same shared GPU pool rather than dedicating separate hardware to each.

How can AI infrastructure keep running without a stable internet connection?

AI infrastructure that needs to run at field sites or disconnected locations has to keep operating on its own and reconcile automatically once connectivity returns, rather than depending on a live link back to a central datacenter. Kubermatic’s KubeLB and KKP give BWI exactly that: the same Kubernetes and load-balancing architecture that runs BWI’s core datacenters is also deployed at a disconnected field site, so AI capability there doesn’t depend on network uptime.

What causes vendor lock-in in AI infrastructure, and how do you avoid it?

Vendor lock-in happens when an AI platform is built on one cloud or hardware vendor’s proprietary technology, leaving the organization dependent on that vendor’s pricing and roadmap. Kubermatic avoids this by building on open-source Kubernetes and virtualization technology instead of a proprietary stack. BWI runs its GPU infrastructure on Kubermatic for exactly this reason, keeping full control over how the environment evolves.

What is Kubermatic AI?

Kubermatic AI is Kubermatic’s platform for running GPU-powered AI workloads on Kubernetes. It combines multi-tenant cluster management (KKP), GPU virtualization (Kubermatic Virtualization), load balancing (KubeLB), and a self-service catalog (KDP), so organizations can share GPU infrastructure across teams without sharing access to each other’s data.

Why bring in a delivery partner for a large public-sector AI project?

Large public-sector AI projects need both deep infrastructure expertise and a working knowledge of the customer’s environment, procurement processes, and stakeholders, and rarely does one vendor have both. On the BWI project, Kubermatic brought the Kubernetes and cloud-native engineering behind Kubermatic AI, while SVA brought its long-standing relationship with BWI, shaping how the platform fit the customer’s actual requirements from first concept through implementation.

Is BWI's AI infrastructure sovereign?

Yes. The platform runs entirely on BWI-owned and operated infrastructure, with no dependency on foreign cloud providers. It’s built on Kubermatic’s open-source stack, so BWI is not locked into a single vendor’s proprietary technology for how the platform evolves.

Can the platform run outside the core datacenter?

Yes. The same Kubermatic AI architecture that runs BWI’s core datacenter clusters is also deployed at a disconnected field site. KubeLB and KKP are designed to keep operating and reconcile automatically once connectivity is restored, so losing a connection doesn’t mean losing the capability.

Want to see what Kubermatic AI could do for your organization? Get in touch with the Kubermatic team to talk through your GPU infrastructure requirements.

Leading Companies Choose Kubermatic

Allianz Vonage CNCF Cube FHE3 Switch inventx Datagroup Krone Charite Justus-Liebig-Universität Gießen Heidelberg University Swisscom Datev BWI