Opens in a new tab
vmblog logo 2024 wht (updated)

Spacelift's Pawel Hytry on Intent-Driven Infrastructure: Moving Beyond the Speed vs. Safety Trade-off at KubeCon NA 2025 – VMblog QA

Share: 

As enterprises grapple with the tension between innovation velocity and operational control, Spacelift is arriving at KubeCon + CloudNativeCon North America 2025 with a provocative message: infrastructure teams shouldn’t have to choose between moving fast and maintaining governance. The company’s newly launched Intent feature represents a fundamental rethinking of how AI can participate in infrastructure provisioning, not as a replacement for established IaC and GitOps workflows, but as a complementary tool for everything that lives between prototype and production. At Booth 541 and during OpenTofu Day on November 10, Spacelift will demonstrate how natural language provisioning can coexist with policy-as-code guardrails, offering teams a faster control plane without sacrificing auditability or compliance.

For Pawel Hytry, Co-founder and CEO of Spacelift, the company’s KubeCon presence reflects both its open-source roots and its vision for autonomous infrastructure orchestration. As a Silver Sponsor of the main event and a supporter of OpenTofu Day, Spacelift is doubling down on its commitment to the cloud-native community while addressing a challenge that resonates across the show floor: how to trust AI with infrastructure decisions. In this exclusive VMblog Q&A, Hytry explains why the answer isn’t blind trust but deliberate governance, and why enterprises should start thinking about their infrastructure lifecycle as a continuum rather than a binary choice between experimentation and production readiness.

++

VMblog: Can you give us your elevator pitch? What key message will attendees hear from you at KubeCon NA 2025, and what actionable insights will they take back to influence their management teams?

Pawel Hytry:  Our message at KubeCon is that infrastructure-as-Code solves a real problem, but it also introduces a new one: ceremony when ceremony is not warranted. We’re going to be talking about Intent, which is our answer that provides an operationally viable companion to heavyweight IaC/GitOps workflows when heavyweight production ceremony is not required.

Today, engineers face a really bad choice: move fast and lose control, or move safely and lose time. Intent fills that gap by leveraging AI to translate human intent directly into infrastructure, with guardrails to provide governance. With it, you can move fast and still remain fully auditable.

None of this is about replacing Terraform or GitOps. It’s about giving teams another option for everything that lives between prototype and production. Intent keeps speed, state, and safety in balance so engineers can focus on outcomes instead of ceremony.

The key takeaway for attendees is this: You don’t have to choose between innovation and compliance. Infrastructure should start where developers actually work, in natural language and context. Move to maturity and IaC only when it adds value for production environments.

If you take one actionable idea back home from Atlanta, it’s this: rethink your infrastructure lifecycle as a continuum, not a binary decision. Use the right level of governance for the right stage of work. Let your teams experiment safely, move fast, and promote what works into production without rewriting everything twice.

That’s the world we’re building with Spacelift Intent, answering the question everyone’s quietly asking: “How can I trust AI to run my infrastructure?” The short version is that you don’t trust it blindly, you govern it deliberately. Intent was built from the ground up with human-in-the-loop controls: it runs inside your existing cloud accounts, under your established roles, and within your own policy-as-code guardrails. Every action it takes is auditable, reversible, and state-aware. It doesn’t work outside your defined boundaries: it interprets your intent, applies your policies, and shows its work.

So instead of asking teams to take a leap of faith on AI, Intent gives them the scaffolding to use it safely, turning “trust” from a feeling into a framework.

VMblog: As a sponsor of KubeCon + CloudNativeCon North America 2025, what sponsorship level have you chosen, and what strategic objectives drove this investment?

Hytry:  We’re silver sponsors of the main event, and we’re also sponsoring OpenTofu Day on Monday. These are great choices for startups like us who need visibility at the event combined with support for specific community projects that mean a lot to us and our customers.

VMblog: Where can attendees find you at the event? What hands-on demos, interactive experiences, or booth activities have you designed to showcase your technology?

Hytry:  Spacelift will be on the KubeCon show floor at Booth 541 with live demos of Spacelift Intent, giving attendees a chance to see natural language provisioning in action. You’ll be able to describe the infrastructure you want (“Create a Kubernetes cluster with two nodes and attach it to my existing VPC”) and watch it safely deploy through your governance guardrails.

We’re also proud to participate in OpenTofu Day, the official colocated event, where Spacelift engineer Christian Mesh will present “OpenTofu’s Performance Pillars, Pitfalls, and Profiling.” His session dives into performance tuning and profiling best practices for OpenTofu – insights that directly influence how Spacelift optimizes orchestration at scale.

Across both venues, we’ll feature hands-on sessions exploring OpenTofu workflows, policy-as-code in action, and multi-IaC orchestration for complex hybrid environments – all designed to help teams experience the future of governed, AI-driven automation.

Also, a not-to-miss event for anyone in the IaC space: IaCConf Connect on November 10 at Wild Leap Atlanta. After a fantastic debut of virtual IaCConf in May and IaCConf Spotlight: Security + Governance in August , we are gathering in person! Join us for a pint and a snack, a panel of industry pros, and mingling after the first day of KubeCon.

VMblog: How has your company’s KubeCon presence evolved since your first participation? What value keeps driving your continued investment in this community?

Hytry:  Spacelift’s roots are in open source – and that community connection is what keeps bringing us back. Our presence has evolved from introducing our IaC orchestration platform to now shaping the future of infrastructure automation with AI-driven orchestration innovation.

KubeCon represents the best of what’s possible when developers and operators collaborate across tools and ecosystems. It’s where we engage with the builders who make cloud-native infrastructure work at scale.

VMblog: Can you dive deeper into your company’s core technologies? What specific challenges do you solve for KubeCon attendees in their day-to-day operations?

Hytry:  Spacelift sits at the intersection of automation, governance, and developer productivity. For KubeCon attendees, that means solving everyday challenges like:

  • Policy enforcement at scale: defining and automating guardrails through OPA-based policy-as-code.
  • Multi-tool orchestration: combining OpenTofu, Terraform, Kubernetes, Pulumi, and Ansible workflows in a single governed pipeline.
  • Drift detection and remediation: continuously monitoring for configuration drift and auto-correcting when systems diverge from their intended state.
  • Flexible deployment: supporting SaaS, self-hosted, cloud, and air-gapped models for regulated industries.

Now with Intent, Spacelift also removes the need for HCL expertise in early prototyping and testing, letting engineers go from “idea to infrastructure” in seconds – safely and transparently.

VMblog: In an increasingly saturated cloud-native marketplace, what distinguishes your solution in late 2025? What’s your unique value proposition?

Hytry:  Well, it’s arguably the case that intent-driven infrastructure management is current, topical, and even frothy. Doing it while retaining policy and auditability is novel and unique. We’re looking forward to having that conversation with everyone in Atlanta.

VMblog: With GenAI workloads and LLM deployments reshaping cloud-native architectures, how does your solution address these AI infrastructure demands?

Hytry:  It’s an interesting question, because the reality is GenAI and LLM workloads are blowing up the assumptions we’ve had about infrastructure. These systems are insanely dynamic and constantly changing, especially with the inference endpoints that spin up and down hourly. You can’t manage that kind of elasticity with heavyweight, pipeline-driven infrastructure workflows.

Intent provides a path for teams to have a faster control plane for AI-native infrastructure, a way to describe what they need in plain language, get it provisioned quickly, and still have policy and state baked in. You can use it to spin up an ephemeral training environment, test a new model variant, or sandbox an inference stack without writing 200 lines of HCL every single time. And because Intent tracks everything it builds, you don’t lose visibility when experiments move fast and move on to production.

So as GenAI architectures get more fluid, Intent makes it possible to keep governance and reproducibility anchored, even when the workloads riding atop are anything but. Sounds a little optimistic maybe, but it’s how you can keep AI moving at AI speed without giving up control of the cloud underneath it. Especially as we look to the very possible future of AI agents looking to deploy their own infrastructure, a use case that Intent can handle already.

VMblog: How does your technology fit within the broader CNCF ecosystem? What’s your role in the modern cloud-native infrastructure stack?

Hytry:  Spacelift is the orchestration and governance layer that sits above the CNCF ecosystem. It integrates tightly with Kubernetes, automates provisioning with OpenTofu/Terraform, and enforces policy-as-code to keep everything compliant and consistent.

We’re also an active contributor to the CNCF landscape through OpenTofu, which has become the community-driven, vendor-neutral standard for Infrastructure as Code. Spacelift’s team contributes directly to OpenTofu’s evolution and helps enterprises adopt it at scale, bringing together open standards and enterprise-grade automation.

VMblog: Are you unveiling any new products, features, or partnerships at KubeCon NA? What exclusive announcements can attendees expect? 

Hytry:  Yes – KubeCon is the first major showcase for Spacelift Intent, launched this October. Intent introduces natural language provisioning that’s secure by design, open by nature, and fully governed by your existing policy frameworks.

It’s an early look at where the industry is heading: agentic automation that understands intent, executes infrastructure safely, and learns from organizational policy over time. We’ll also highlight new integrations that extend Spacelift’s orchestration capabilities deeper into cloud-native workflows, including Kubernetes and observability pipelines.

VMblog: With platform engineering gaining momentum, how do you support organizations building internal developer platforms and improving developer experience?

Hytry:  Platform teams use Spacelift to abstract away IaC complexity and provide self-service experiences for developers.

Our Blueprints feature lets teams predefine golden paths: reusable infrastructure templates governed by policy so developers can spin up compliant environments without waiting on operations.

With Intent, this experience becomes even more intuitive. Developers can use natural language to request what they need, and the platform translates that intent into governed infrastructure. It’s the next evolution of platform engineering where you combine developer freedom with operational control.

VMblog: What’s your take on the convergence of security-by-design and cloud-native development in 2025? How do you help customers implement secure-by-default practices?

Hytry:  Security is a first-class citizen in Spacelift’s architecture. Our philosophy is secure enablement: making guardrails invisible but effective.

Through policy-as-code, Spaces (isolated control environments), and drift detection, teams can enforce compliance automatically,  not as an afterthought. With Intent, those same policies extend to AI-assisted provisioning, ensuring that even natural language requests adhere to organizational rules.

This bridges a critical gap. AI-powered speed without governance risk is how teams can adopt secure-by-default practices while still moving fast.

VMblog: Are you hosting any exclusive events, networking sessions, or after-hours meetups during KubeCon? How can attendees participate?

Hytry:  Yes. We’re hosting the first in person gathering of the IaCConf community. The event is called IaCConf Connect, and it’s taking place at Wild Leap Atlanta on Monday, November 10, from 6-9pm. Along with food, drinks, and networking, we’ll feature a panel discussion among industry experts, including Ned Bellavance, Luke Phillips, and Rob Strechay. Register to join us!

VMblog: Looking ahead to 2026 and beyond, how do you see the cloud-native landscape transforming? What should enterprises be strategically planning for?

Hytry:  We’re entering the era of autonomous infrastructure orchestration, where systems understand user intent, learn from historical context, and self-correct without manual intervention.

For enterprises, this means preparing for hybrid automation stacks that blend human input, AI assistance, and open-source interoperability. The winners will be those who can balance innovation and governance, using platforms like Spacelift to unify policy, visibility, and trust across all infrastructure layers.

The next frontier isn’t just more automation; it’s automation that natively understands you.

##