Agentic Data Plane

Create an Agentic Data Plane Environment

Create a Redpanda Agentic Data Plane environment to build and govern agents in your Amazon Web Services (AWS) account or Google Cloud Platform (GCP) project through BYOC.

After reading this page, you will be able to:

  • Configure an environment’s cloud provider, region, and network access

  • Provision the environment with the generated rpk command

  • Verify readiness and open the environment

Prerequisites

  • A Redpanda Cloud organization with a plan that includes Agentic Data Plane for your chosen cloud provider. The organization needs available quota for Agentic Data Plane environments, BYOC networks, and BYOC cores. Contact Redpanda Support to confirm access and quotas or request higher limits.

  • Permission to create clusters in the resource group you select. If you don’t have it, ask your organization administrator to grant it.

  • rpk installed on the machine where you run the apply command.

  • Credentials for the target AWS account or GCP project, with permission to provision BYOC infrastructure. Ask your cloud administrator to prepare this access. For credential setup, see the AWS credential configuration or Google Cloud authentication documentation. Redpanda Cloud authentication does not replace these cloud-provider credentials.

  • An IPv4 CIDR block that does not overlap any network you plan to connect to the environment. Review CIDR range guidelines.

  • If you plan to choose Private access, a network path from your computer to the environment’s virtual private cloud (VPC), such as a VPN, VPC peering, AWS PrivateLink, or Google Cloud Private Service Connect. Without one, you can’t open the environment in the Agentic Data Plane UI or use rpk ai against it. Plan the connection before you create the environment.

Configure the environment

The Cloud UI records your settings. You then run an rpk command to start provisioning in your cloud account.

  1. Sign in to the Redpanda Cloud UI and select the organization where you want to create the environment.

  2. In the navigation menu, click Agentic Data Planes, then click Create Agentic Data Plane.

  3. In the Details section, configure these fields:

    Field What to enter

    Name

    A name unique within your organization, such as example-environment. Use one to 63 lowercase letters, numbers, or hyphens. Start with a letter and end with a letter or number.

    Resource group

    Select a resource group where you have permission to create clusters, or confirm the preselected group if one is shown.

    Cloud provider

    AWS or Google Cloud. The form offers only providers included in your organization’s plan.

    Region

    An available region in your selected cloud provider.

    Creation form showing an example environment name, resource group, cloud provider, and region
    Figure 1. The creation form with example AWS settings
  4. In the Networking section, choose API gateway access:

    • Public (default): The Agentic Data Plane UI and rpk ai can reach the environment from the internet. Authentication and authorization apply.

    • Private: The Agentic Data Plane UI and rpk ai can reach the environment only from networks connected to the VPC.

      Private means private. From any computer that isn’t connected to the environment’s VPC through a VPN, VPC peering, AWS PrivateLink, or Google Cloud Private Service Connect, the Agentic Data Plane UI at ai.redpanda.com can’t load the environment and rpk ai commands against it time out. Signing in to ai.redpanda.com and selecting the environment still work from anywhere. Everything after that needs the private network connection. Choose Private only if that connection is in place, or planned, for everyone who will use the environment.

      You choose this setting when you create the environment. To change it later, an administrator edits API gateway access on the environment’s Dataplane settings page in the Redpanda Cloud UI. This option isn’t available to every organization, so choose carefully.

  5. Set Redpanda Network IP CIDR block. The default is 10.0.0.0/16. Use an RFC 1918 private IPv4 network range with a prefix length from /16 to /20 on AWS, or /16 to /19 on GCP. The range must not overlap networks connected to the VPC.

  6. If you selected AWS and Private access and the form shows Egress Transit Gateway ID (optional), leave it empty to use the default NAT gateway path. To use an existing AWS Transit Gateway for outbound traffic instead, enter its ID.

    The Transit Gateway must be in the same AWS account and region, accept VPC attachments, and have hub routes that do not overlap the environment’s CIDR block. This optional field is available only for organizations with Transit Gateway egress enabled. It does not configure client access to the environment.

    Networking section showing private API gateway access, the CIDR block, and an empty optional Transit Gateway field
    Figure 2. AWS networking settings with private access selected and the optional egress field available
  7. Click Create Agentic Data Plane.

  8. Wait for State to show Apply required on the environment’s detail page. Creating the entry in the Cloud UI does not provision the environment by itself.

Apply the configuration

Run the generated command from a terminal with the cloud-provider credentials prepared in the prerequisites.

  1. Sign in to the same Redpanda Cloud organization you used in the Cloud UI:

    rpk cloud login

    For authentication options, see rpk cloud login.

  2. On the environment’s detail page, find the Apply command section. If you selected Google Cloud, enter your target project ID in GCP project ID to enable Copy command.

  3. Click Copy command and run the copied command in your terminal. The Cloud UI fills in the environment ID. The commands have these forms:

    AWS
    rpk cloud byoc aws apply --redpanda-id <environment-id>
    Google Cloud
    rpk cloud byoc gcp apply --redpanda-id <environment-id> --project-id '<project-id>'

    <environment-id> is the environment’s ID on the detail page. <project-id> is the GCP project where you want to provision it. Use the generated command rather than copying these placeholders unchanged.

  4. Wait for the command to complete successfully. If it fails, resolve the reported error before continuing. Redpanda Cloud then provisions the infrastructure and installs the services. The environment shows Creating while provisioning continues.

Verify and open the environment

  1. Return to the environment’s detail page and wait for State to show Ready.

  2. Confirm that the Endpoints section lists AI Gateway URL and API URL.

  3. If you selected Private access, connect your computer to the environment’s VPC first. From a browser outside that network, ai.redpanda.com can’t load the environment and instead asks you to connect to your private environment.

  4. Click Open and confirm that the Agentic Data Plane UI loads for your environment. The Open button appears when the environment is Ready.

Troubleshooting

Symptom Action

The navigation menu has no Agentic Data Planes entry, or the page shows Agentic Data Planes unavailable.

Confirm that you selected the intended organization. Contact Redpanda Support to check that its plan includes Agentic Data Plane for your cloud provider.

The page shows Creation unavailable.

Read the accompanying message. Creation may not be enabled, or the organization may have reached its limit. Contact Redpanda Support to enable creation or raise the limit.

Create Agentic Data Plane is disabled.

Complete the required fields and resolve validation errors. If the page reports a loading error, use its retry control. Confirm that you have permission to create clusters in the selected resource group. Ask your organization administrator to grant access if needed.

The creation form shows Creation timed out or Creation not confirmed.

Keep the form open and submit the same values again without reloading the page. Creation may still be in progress. Submitting unchanged values from the same form reuses the original request rather than allocating a duplicate.

The page shows Creation progress unavailable.

On the creation form, click Retry. On the environment’s detail page, click Retry progress. These controls retry the progress lookup without allocating another environment. If progress remains unavailable, contact Redpanda Support with the environment name and its ID if available.

The creation form shows Creation failed before the environment’s detail page opens.

Read the accompanying message and resolve any reported name or Transit Gateway conflict. For other allocation errors, contact Redpanda Support with the environment name and region, and ask them to check the organization’s Agentic Data Plane, BYOC network, and BYOC core quotas.

The environment remains in Apply required.

Run the command from its Apply command section with credentials for the target cloud account. Check the terminal output for errors. If it reports that the agent token is not provisioned yet, wait briefly and retry the same command.

The environment remains in Creating after the apply command completes.

Allow provisioning to finish. If the state does not progress to Ready, contact Redpanda Support with the environment ID and displayed status. Do not create a replacement environment to retry provisioning.

The environment shows Failed.

Contact Redpanda Support with the environment ID and the error shown. Cloud resources may remain after failed provisioning. Do not assume the failure removed them.

The environment is Ready, but ai.redpanda.com asks you to connect to your private environment, rpk ai warns that the environment is private, or an endpoint times out.

Your computer isn’t on a network connected to the environment’s VPC. Connect through your organization’s VPN, VPC peering, or private endpoint service, then click Reload page in ai.redpanda.com or rerun the rpk ai command. Test from the intended client network, not an unrelated internet connection. If access still fails, contact Redpanda Support with the environment ID.

Next steps