Avi Load Balancing in VCF 9.1 Self-Service Delivery and the First LB Features Built for Agentic AI

Automated load balancing within guardrails on one front; MCP session persistence, JWT authentication, and tool RBAC on the other. The load balancing layer catches up with where the platform is going.

Share

Load balancing has been the network service most likely to still require a ticket in otherwise self-service estates. And no network service has yet had a good answer for agentic AI traffic. Avi’s VCF 9.1 innovations address both fronts which makes this release the moment the LB layer catches up with the platform’s direction.

Front One Self-Service Within Guardrails

Automated load balancing in VCF 9.1 places LB provisioning in application-team hands, governed by central guardrails the same operating pattern as Self-Service Lateral Security with vDefend. Application teams provision load balancing and micro-segmentation within policy; the platform team defines the policy rather than processing the tickets. Avi services VPC workloads natively, so LB provisioning composes with the self-service networking surface (VPCs, private network exposure, gateway firewalls) rather than sitting beside it.

For VCSP and MSP operators, this is directly monetisable: tenant-self-service LB within provider-defined guardrails reduces provider operational cost per tenant while improving tenant time-to-service. For enterprise platform teams, it removes one of the last per-change touchpoints between application delivery and the network team.

Front Two The Agentic AI Traffic Class

The forward-looking piece: Avi adds MCP (Model Context Protocol) support session persistence for MCP connections, JWT authentication, and RBAC for MCP tools.

Why the LB layer needs to understand MCP: agentic AI workloads hold stateful conversations with tool servers. Sticky routing keeps an agent’s session on a consistent backend; JWT authentication ensures tool access is authenticated at the network entry point; RBAC on MCP tools scopes which callers can reach which tools. As enterprises deploy AI agents that call tools over MCP and VCF 9.1’s MCP Support with Governance connects Oracle, SQL Server, ServiceNow, GitHub, Slack, and PostgreSQL the load balancing layer becomes an enforcement point for session integrity and tool authorisation, not just a traffic distributor.

Design Guidance

If a customer is piloting agentic AI on VCF, design the Avi layer and the MCP governance layer together, not sequentially. The tool-access RBAC conversation spans both: governance defines which agents may use which tools; Avi enforces authenticated, role-scoped, session-consistent access at the network level. Retrofitting the network enforcement after the pilot has scaled is the predictable failure mode the pilot works, production inherits the pilot’s absent controls.

The Architect’s Takeaway

Avi in 9.1 tells one story on two fronts: network services move to self-service within guardrails, and the guardrails extend to the newest workload class before it scales. Put self-service LB in the tenancy design, put MCP session and authentication handling in every agentic AI architecture, and treat the LB layer as a security enforcement point because in 9.1, it finally is one.

Sources

Broadcom Avi Innovations for VCF 9.1: Powering Kubernetes, Agentic AI and VPC Workloads

Broadcom Streamline, Simplify and Protect all your AI workloads with VCF 9.1

Broadcom Announcing VCF 9.1: Modern Private Cloud Built for Efficiency and Resilience

Broadcom Monetizing Zero-Trust Security with VCF 9.1 and VMware vDefend