# WEKA (NeuralMesh + NeuralMesh Axon + WEKApod + Augmented Memory Grid + the WEKA Operator, CSI Plugin, App Store, and AI Data Platform) — 4+1 Layer AI Infrastructure Assessment

> Mapped to the 4+1 Layer AI Infrastructure Model  
> Version: v1.0 - 4+1 v2: Authority Split · Date: September 10, 2026  
> Source: NeuralMesh documentation at docs.weka.io (version 5.1: S3 protocol, limitations, versioning, object lock, lifecycle rules, bucket notifications, audit webhook, users and authentication with LDAP and OIDC, performance buckets; CSI plugin and topology-aware provisioning; prerequisites and compatibility; AWS, Azure, GCP, and OCI installation and Terraform modules; Cloud Deployment Manager; KMS management; release support and commitments; the WEKA App Store and the WEKA AI Data Platform installation guides; the llms.txt documentation index; version 5.0: NeuralMesh Axon overview, deployment, and maintenance; WEKA Operator deployments and day-2 operations; Composable Clusters; Organizations; licensing overview and classic license; bare-metal installation paths; SMB-W; monitoring with Prometheus and Grafana; Local WEKA Home security and compliance; stateless client best practices); weka.io product pages (NeuralMesh, NeuralMesh Axon, Augmented Memory Grid, WEKApod); WEKA press releases (WEKA Breaks the AI Memory Barrier with Augmented Memory Grid on NeuralMesh, November 18, 2025; WEKA Unveils WEKApod 3, July 21, 2026; WEKA Debuts NeuralMesh 6, July 22, 2026; WEKA and Andromeda Partner, July 30, 2026) and the OCI article; GitHub license API for weka/csi-wekafs. Peer-reviewed cell by cell through the labs claims ledger (weka-<layer>-chatgpt, ChatGPT gpt-5.5) and as a whole row by Antigravity (weka-row-agy); totals and escalated items in reviews/weka-judgment.md.  
> Published by: The CTO Advisor LLC (DBA The Advisor Bench) · thectoadvisor.com  
> Author: Keith Townsend

[Full interactive assessment](https://layer2c.com/assessment/weka) · [Methodology](https://layer2c.com/methodology) · [What Is Layer 2C?](https://layer2c.com/what-is-layer-2c)

## Executive Summary

WEKA is a storage software company that has renamed its product for the inference era: NeuralMesh (documentation version 5.1) is the WEKA Data Platform, and around it sit NeuralMesh Axon (the filesystem converged onto GPU servers), WEKApod appliances, the Augmented Memory Grid (key-value cache tiering to NVMe for inference engines), and, in 5.1, a Data Catalog, a WEKA App Store, and an AI Data Platform blueprint. The map reads it moderate at five layers and gap at three, with no strong cell. Layer 1A is the deepest cell, moderate at the top of the band: one multi-protocol namespace with a native S3 service (object lock, versioning, audit), a Data Catalog that indexes and queries filesystem metadata at scale, tenants two ways (Organizations and hardware-isolated Composable Clusters), and encryption under the enterprise's key management system (KMS), with no classification or lineage. Layer 0 is moderate on software-defined storage over servers the enterprise picks from WEKA's support matrix or clouds it rents. Layer 1B is moderate on the AI Data Platform: a filesystem watcher feeding NVIDIA NeMo Retriever and Milvus, with file permissions enforced at query time when identity is federated. Layer 1C is moderate on object-store tiering (with per-path overrides) and snap-to-object plus the platform's ingest pipeline; the Augmented Memory Grid, commercially available since November 2025, has no documentation page and is named, not scored, and escalated as an instrument question. Layer 2A is moderate on the WEKA Operator with node-selector pins, the Cloud Deployment Manager, Terraform modules, and an open CSI driver, with no compute scheduling. Layer 2B is moderate, with Everpure's, on the AI Data Platform's agentic RAG surface: NVIDIA's blueprint behind WEKA's gateway. Layer 2C is a gap: the platform's identity, gateway, and traces are application-scoped legs. Layer 3 is a gap: the App Store's documented catalogue is one data pipeline.

The capture is at the filesystem and nowhere below it. NeuralMesh, its client and data path, the Data Catalog, the Operator, the installers, the App Store, NeuralMesh Observe, and the AI Data Platform's gateway are WEKA's; that's why 11 of the 15 components read Ceded. What lifts: the servers, drives, and adapters the enterprise buys from any vendor on WEKA's matrix; the NFS and SMB doors and a subset of S3 (buckets, policies, versioning, object lock); and the open-source CSI driver at the Kubernetes standard. NVIDIA's NIMs inside the AI Data Platform are Ceded to NVIDIA under the channel-substitution rule; GPUDirect Storage, NIXL, and Dynamo are the inference stack the enterprise brings, not a dependency the filesystem carries.

The buyer's trade: a parallel filesystem on hardware it chooses, in clouds it already rents, that can describe its own metadata and isolate tenants it can bill, plus a packaged retrieval and RAG stack over it, in exchange for the filesystem's layout, catalog, tenancy, tiering, and control plane being WEKA's and the retrieval and generation engine being NVIDIA's. The decision-authority readings follow: vendor / Ceded at Layer 0, 1A, and 1B (NeuralMesh stripes, isolates, and answers per policies the enterprise set); vendor / Delegated at 1C and 2A on documented overrides (per-path tier fetch and release; node selectors and tolerations on the enterprise's own Kubernetes); model / Ceded at 2B (NVIDIA's model over the platform's index, no swap, no gate); Absent at 2C and Layer 3. What would move cells: Augmented Memory Grid documentation (a scored 1C chip and, with NeuralMesh 6's replication in the second half of 2026, an argument for strong), classification in the Data Catalog (1A, to strong), a WEKA-fronted generation endpoint with model choice (2B), documented applications in the App Store (Layer 3), and WEKApod 3 shipping in Fall 2026 (nothing moves; watch-listed).

## Layer Status

| Layer | Status | Classification |
|---|---|---|
| Layer 0 · Compute | ◑ NeuralMesh, Software-Defined Storage and Memory on Commodity NVMe Servers You Own, Your Cloud Accounts (AWS, Azure, GCP, OCI), or WEKApod Appliances; No Compute, No Fabric; WEKApod 3 Ships Fall 2026 | Compute & Network Fabric |
| Layer 1A · Storage | ◑ One Parallel Filesystem Behind POSIX, NFS, SMB, and a Native S3 With Object Lock, Versioning, and Audit; a Data Catalog That Indexes and Queries Filesystem Metadata at Scale; Organizations and Composable Clusters for Tenants; Encryption Under Your KMS; No Classification, No Lineage | Data Storage & Governance |
| Layer 1B · Retrieval | ◑ The WEKA AI Data Platform From the App Store: a Filesystem-Watching Ingest, NVIDIA NeMo Retriever Embedding, and Milvus Vector Index With POSIX Permissions Enforced at Query Time; the Engine Is NVIDIA's and Milvus, the Packaging Is WEKA's | Context Management & Retrieval |
| Layer 1C · Pipelines | ◑ Object-Store Tiering and Snap-to-Object for Cost-Aware Movement, AIDP's Continuous Ingest as a Fixed Pipeline; the Augmented Memory Grid's KV Cache Tiering Is Commercially Available but Undocumented; NeuralMesh 6 Replication Pending | Data Movement & Pipelines |
| Layer 2A · Orchestration | ◑ The WEKA Operator and Cloud Deployment Manager Run NeuralMesh on the Enterprise's Kubernetes and Clouds (Custom Resources, Rolling Upgrades, Auto-Scaling Groups, Composable Tenants); a Standard CSI Door; Node Selectors and Tolerations Pin Where WEKA Runs; No Compute or GPU Scheduling | Infrastructure Orchestration |
| Layer 2B · Runtime | ◑ The AI Data Platform's Agentic RAG API: NVIDIA NIM Inference Services, a RAG Server, and WEKA's RAG Gateway and RAG Bridge Answering Over the Platform's Own Index; No General Serving, No Agent Runtime; the Augmented Memory Grid Feeds Other Engines | Application Runtime & Execution |
| Layer 2C · Reasoning | ○ Tenant Isolation and Permission-Aware Retrieval Govern Data, Not Agents; Keycloak Inside AIDP Identifies Users; Not a Plane | Agentic Infrastructure — The Reasoning Plane |
| Layer 3 (+1) · Applications | ○ No Application: the App Store Deploys One Documented Blueprint, the AI Data Platform, Which Is a Data Pipeline; the Catalogue's Breadth Is Undocumented | AI Application Layer — The Value Plane |

## DAPM Portability Profile (components)

| Classification | Count | Meaning |
|---|---|---|
| Retained | 1 | I possess the capability and can operate it independently of this provider |
| Delegated | 3 | Someone else provides the capability, but I can substitute that provider without reconstructing my accumulated opinions |
| Ceded | 11 | Changing providers requires reconstructing those opinions |

**Decision authority (per layer, gaps included)**

| Reading | Layers | Meaning |
|---|---|---|
| Retained | 0 | The enterprise, or code it writes or controls, decides |
| Delegated | 2 | Vendor or model decides; the enterprise can see and override |
| Ceded | 4 | Vendor or model decides; no override, often invisible |
| Absent | 2 | Nothing offered, nothing inherited |

## Gap Areas

- **Layer 2C** (Agentic Infrastructure — The Reasoning Plane) — Tenant Isolation and Permission-Aware Retrieval Govern Data, Not Agents; Keycloak Inside AIDP Identifies Users; Not a Plane
- **Layer 3 (+1)** (AI Application Layer — The Value Plane) — No Application: the App Store Deploys One Documented Blueprint, the AI Data Platform, Which Is a Data Pipeline; the Catalogue's Breadth Is Undocumented

## Layer-by-Layer Detail

### ◑ Layer 0 · Compute: Compute & Network Fabric

*Raw compute, networking, and acceleration fabric*  
**Status:** NeuralMesh, Software-Defined Storage and Memory on Commodity NVMe Servers You Own, Your Cloud Accounts (AWS, Azure, GCP, OCI), or WEKApod Appliances; No Compute, No Fabric; WEKApod 3 Ships Fall 2026

**Decision authority:** Ceded (decides: vendor; visible: true; overridable: false; boundary: vendor)

**NeuralMesh Software (Version 5.1; Backends and Clients in Containers; the WEKA Client Driver and Proprietary DPDK or UDP Data Path; Bare-Metal Installers; Terraform Modules and Cloud Deployment Manager for the Enterprise's AWS, Azure, and GCP Accounts; OCI Bare-Metal Workflow; NeuralMesh Axon Converged on GPU Servers)** [DAPM: Ceded]  
WEKA's filesystem software, its client, its data path, and its installers, on hardware or cloud instances the enterprise owns. Ceded, the VAST and NetApp reading; the cloud substrate is scored on the cloud's row.

**The Enterprise's Servers, NVMe Drives, Adapters, and Switches (Supported Intel, AMD, or NVIDIA Grace CPUs; Power-Loss-Protected NVMe Within WEKA's Capacity Ratios; Adapters From WEKA's Matrix; InfiniBand or Ethernet)** [DAPM: Retained]  
Hardware the enterprise buys from any vendor on WEKA's support list and runs NeuralMesh on. Retained, the Nutanix multi-vendor hardware reading; the matrix narrows the choice without owning it.

**WEKApod Appliances (Nitro, Prime, Prime Max; WEKApod 3 Announced July 21, 2026, Delivery Fall 2026)** [DAPM: Ceded]  
WEKA-engineered systems with NeuralMesh preinstalled, sold through distributors. Ceded; the third generation is watch-listed, not scored.

**Front-End Protocols (NFS, SMB, S3; InfiniBand and Ethernet)** [DAPM: Delegated]  
Standards the enterprise's hosts speak; the filesystem behind them is WEKA's, and the native WEKA client is WEKA's driver over a proprietary data path, scored in the software chip. Delegated, the NetApp storage-networking reading. GPUDirect Storage is NVIDIA's cuFile stack and sits in the NVIDIA note.

**Gap Analysis:** WEKA sells software; the enterprise picks the hardware under it, within WEKA's support matrix. NeuralMesh (the WEKA Data Platform renamed; current documentation is version 5.1, with 5.0 and the 4.4 long-term-support release still supported) installs on supported Intel, AMD, or NVIDIA Grace servers with power-loss-protected NVMe drives dedicated to WEKA (up to 30 TB, within WEKA's capacity-ratio rules, auto-detected by the configurator), qualified InfiniBand or Ethernet adapters from WEKA's adapter matrix (ConnectX-4 dropped in 5.1.0) running WEKA's Data Plane Development Kit (DPDK) data path or UDP mode, a minimum of eight servers, through three paths: the WEKA Management Station and Software Appliance on Dell, HPE, Supermicro, or Lenovo servers, the appliance alone on any UEFI server (Rocky 8.6), or a manual install on the enterprise's own OS; in the enterprise's own AWS, Azure, and GCP accounts through WEKA's Terraform modules with auto-scaling groups and a Cloud Deployment Manager wizard that generates the artifacts, and on OCI bare-metal shapes through a manual, bare-metal-style workflow WEKA asks the enterprise to coordinate with OCI; as NeuralMesh Axon, converged onto the GPU servers themselves ('storage and compute services run on the same physical infrastructure', minimum 32 servers, a fixed 16 plus 4 protection scheme), sold as Core with optional Accelerate, Deploy, Observe, and Enterprise Services; and as WEKApod appliances (Nitro, Prime, Prime Max), whose third generation was announced July 21, 2026 as 'available to order today ... for delivery beginning in Fall 2026'. Licensing is subscription-based per cluster, by edition (XPS, XCL hybrid-cloud, XOS object) with the Data Protection Option (tiering, remote snap-to-object) and Data Efficiency Option as add-ons, keyed to licensed usable flash capacity and object-store capacity; pay-as-you-go was deprecated in version 4.1. The buyer gets a parallel filesystem it can put on whatever it already buys, in whichever cloud it already rents.

The architect's concern is that WEKA is only the storage software. It sells no compute, no GPU, and no fabric; the substrate is the enterprise's servers or the cloud's instances; WEKApod 3 hasn't shipped; and the software is WEKA's alone: a proprietary client and DPDK data path, a four-OEM allow-list on the automated installer, a qualified-adapter matrix, and a single-vendor design in Axon.

Calibration: VAST reads moderate on software-defined storage over commodity boxes; NetApp moderate on a software-defined storage fabric; Everpure moderate on all-flash arrays it builds; Nutanix moderate on a hardware-agnostic abstraction; Dell and HPE strong on compute, fabric, and storage together. WEKA is VAST's and Nutanix's shape: a software substrate on hardware the enterprise picks from a supported list. Moderate.

**Borrowed Judgment:** Retained at the metal, Ceded at the software. The servers, NVMe drives, adapters, switches, and cloud instances are the enterprise's own purchase from any vendor on WEKA's support matrix: Retained, the Nutanix multi-vendor hardware reading. NeuralMesh, its client driver and DPDK data path, its installers, its Terraform modules, and WEKApod are WEKA's: Ceded, the VAST and NetApp reading; NFS, SMB, and S3 are standards: Delegated. The runtime call at this layer is NeuralMesh striping, placing, and rebuilding data across the servers the enterprise gave it, with the protection scheme fixed at configuration and no per-object placement the enterprise reverses: vendor decides, visible (the WEKA GUI, Local WEKA Home, and NeuralMesh Observe), not overridable, Ceded, the VAST and NetApp reading.

### ◑ Layer 1A · Storage: Data Storage & Governance

*Durable, governed data foundation — the Governance Catalog that Layer 2C queries*  
**Status:** One Parallel Filesystem Behind POSIX, NFS, SMB, and a Native S3 With Object Lock, Versioning, and Audit; a Data Catalog That Indexes and Queries Filesystem Metadata at Scale; Organizations and Composable Clusters for Tenants; Encryption Under Your KMS; No Classification, No Lineage

**Decision authority:** Ceded (decides: vendor; visible: true; overridable: false; boundary: vendor)

**NeuralMesh Filesystems Behind POSIX, NFS, and SMB-W (Single Namespace; Snapshots; Quotas; Encryption at Rest With Keys in the Enterprise's Vault or KMIP Server; Snap-to-Object) With the S3 Service's Management Surfaces (OIDC and LDAP Wiring, Audit Webhook, Performance Buckets, Tenant Scoping)** [DAPM: Ceded]  
WEKA's filesystem and protocol implementations in WEKA's layout, and the management surfaces around its S3 door. Ceded, the NetApp ONTAP reading; the keys are the enterprise's behind standard KMS interfaces.

**Native S3 Object Interface (Buckets Over Directories; IAM-Style Policies; STS Credentials; Versioning; Object Lock in Governance and Compliance Modes; Expiration Lifecycle Rules; Kafka Notifications)** [DAPM: Delegated]  
A subset of the S3 interface over the same data; buckets, policies, versions, and locks lift to any S3 store, though server-side encryption, replication, ACLs, CORS, S3 Select, and lifecycle transitions are unsupported. Delegated, the StorageGRID and ObjectScale reading, with the gaps named.

**Data Catalog (Difflist Change Detection Over Rolling Snapshots; Embedded Distributed Query Engine on Data Services Containers; Dedicated Index Filesystem; SQL Query Builder, GUI, and REST API; Growth Forecasts and Point-in-Time Comparison; Metadata Only)** [DAPM: Ceded]  
WEKA's index of WEKA's filesystem metadata, queryable through WEKA's API. Ceded, the NetApp Metadata Engine and Dell MetadataIQ reading; it indexes paths, sizes, and ages, not content or sensitivity.

**Tenancy: Organizations (Up to 256; Admin Separation; SSD and Total Quotas; Root-Only Protocols; No QoS Isolation) and Composable Clusters on Kubernetes (Per-Tenant WekaClusters Over Shared NVMe With Hardware Isolation)** [DAPM: Ceded]  
WEKA's authority and isolation models inside WEKA's cluster. Ceded.

**NeuralMesh Observe and Local WEKA Home (Multi-Cluster Dashboards, Alerting, Administrative Audit, RBAC Groups, Statistics Export API; WEKA Home Itself Is Support-Facing Only)** [DAPM: Ceded]  
WEKA's observability surfaces over WEKA's clusters. Ceded, the Pure1 reading.

**Gap Analysis:** WEKA's data foundation is a single namespace with four doors, a catalog of its own metadata, and two kinds of tenant. NeuralMesh exposes one Portable Operating System Interface (POSIX) compliant parallel filesystem simultaneously through its client, Network File System (NFS), Server Message Block (SMB-W) (SMB 2 and 3 with Multichannel and SMB Direct over RDMA; no high availability in public clouds), and a native S3 service that maps buckets to directories ('A file written via NFS or POSIX is immediately readable via S3'), with IAM-style policies, STS temporary credentials, LDAP and OIDC authentication with short-lived keys, versioning (a one-way cluster setting), Object Lock in governance and compliance modes 'for regulatory requirements, such as SEC 17a-4 and FINRA 4511', lifecycle rules limited to expiration ('does not perform object organization or tiering'), bucket notifications to Kafka, performance buckets that trade S3 compatibility for speed, and an audit webhook to Splunk that replaced bucket logging; the S3 service supports no server-side encryption, replication, ACLs, CORS, or S3 Select. Filesystems encrypt at rest with keys held in the enterprise's key management system (KMS: HashiCorp Vault or any KMIP server), snapshot to object storage, and carry quotas. The Data Catalog (5.1 documentation) indexes and queries filesystem metadata at scale: difflist services on Data Services containers detect changes through rolling snapshots, an embedded distributed query engine stores the metadata in a dedicated index filesystem, and a GUI and REST API answer SQL-builder queries (directories growing more than 50 GB in a day, filesystems reaching 90 percent within fourteen days, files untouched for 90 days), forecast growth, and compare two points in time; it indexes metadata, not content, and does no classification. Tenancy comes two ways: Organizations (up to 256; an Organization Admin the Cluster Admin can't see into; SSD and total quotas for chargeback; protocols only in the root organization; 'no QoS guarantee between organizations') and, on Kubernetes, Composable Clusters (one WekaCluster per tenant over shared NVMe through an SSD proxy, 'complete isolation across drives, processors, and memory'). NeuralMesh Observe (the customer-facing observability platform on WEKA Home's telemetry) and Local WEKA Home hold telemetry, alerts, an audit of administrative actions, RBAC groups, and a statistics export API; WEKA Home itself 'is not accessible to customers directly'. NeuralMesh 6 adds always-on data reduction with a contractual guarantee and 'native multi-tenancy' combining both isolation models, generally available in the second half of 2026. The buyer gets one governed, encrypted, multi-protocol namespace that can describe itself, with tenants it can bill.

The architect's concern is what the catalog knows. It indexes metadata (paths, sizes, ages, owners) for capacity and discovery and does no classification, sensitivity tagging, or lineage; policy stops at the filesystem, bucket, and quota; Organizations isolate authority, not performance; the S3 door is narrower than AWS's; and the S3 identity, audit, and performance-bucket controls around it are WEKA's.

Calibration: NetApp, VAST, and Dell read strong on storage plus a metadata catalog or classification engine; HPE strong on owned storage plus a data fabric; Everpure moderate on fleet governance without a documented catalog; CoreWeave and Nutanix moderate on open or platform storage with a governance tier and no AI-native catalog. WEKA is Nutanix's shape with a better query surface: owned storage plus an index of its own metadata, without the classification or lineage NetApp, Dell, and VAST add. Under the September 15, 2026 ruling, 1A is graded on the catalog Layer 2C can query for what the data is, and a metadata-only index answers where and how big, not what. Moderate, at the top of the band.

**Borrowed Judgment:** Ceded at the filesystem and the catalog, Delegated at the object door. NeuralMesh's filesystem, its protocol implementations, the Data Catalog's index and query engine, Organizations, Composable Clusters, and NeuralMesh Observe are WEKA's with no second implementer: Ceded, the NetApp ONTAP and Metadata Engine reading; the data behind POSIX, NFS, and SMB copies out but the layout, the index, and the services don't. The S3 object, bucket, policy, versioning, and object-lock interface is a subset of a multi-vendor standard and lifts to any S3 store: Delegated, the NetApp StorageGRID and Dell ObjectScale reading, with the unsupported list named; the OIDC and LDAP wiring, the audit webhook, and performance buckets around it are WEKA's management surfaces. Encryption keys stay in the enterprise's KMS behind Vault's API or KMIP. The runtime call is NeuralMesh enforcing the quotas, tenant boundaries, object locks, and expiration rules the enterprise set, with compliance-mode locks deliberately not overridable by any administrator: vendor decides, visible (audit webhook, the GUI, NeuralMesh Observe), not overridable, Ceded, the NetApp, VAST, and Everpure reading.

### ◑ Layer 1B · Retrieval: Context Management & Retrieval

*Low-latency retrieval for RAG — vector/hybrid search, context windows*  
**Status:** The WEKA AI Data Platform From the App Store: a Filesystem-Watching Ingest, NVIDIA NeMo Retriever Embedding, and Milvus Vector Index With POSIX Permissions Enforced at Query Time; the Engine Is NVIDIA's and Milvus, the Packaging Is WEKA's

**Decision authority:** Ceded (decides: vendor; visible: true; overridable: false; boundary: vendor)

**WEKA AI Data Platform (App Store Blueprint: Filesystem Watchers via Snapshot-Diff; NVIDIA NeMo Retriever NIMs and Milvus; RAG Gateway and RAG Bridge Filtering Results by POSIX Permissions at Query Time, Contingent on Federated Identity With UID and GID Attributes; Keycloak; Semantic Search Through a Browser UI or API; Twelve NVIDIA GPUs Across Three Nodes)** [DAPM: Ceded]  
WEKA's packaging, watcher, gateway, and permission model around NVIDIA's retrieval stack and an open index. Ceded to WEKA for the platform and to NVIDIA for NIM under the channel-substitution rule; the generative answer is the 2B chip.

**Gap Analysis:** WEKA's retrieval story arrived with the App Store. The WEKA AI Data Platform (AIDP) deploys from the WEKA App Store catalogue ('Complete a form and select Deploy'): a browser-managed control plane where users create watchers over NeuralMesh filesystems and folders; 'every file created, updated, or deleted is captured through WEKA's snapshot-diff mechanism and reflected in the vector index in real time, without a scheduler, polling interval, or reindex cycle'; selected files are 'parsed, chunked, and embedded using NVIDIA NIM models, then indexed into a vector database, with Portable Operating System Interface (POSIX) permissions captured at ingest and enforced at query time: a user who cannot see a file on the filesystem cannot see its vector either'; users reach semantic search and 'agentic RAG' through a browser UI or API, with the platform's RAG Gateway and RAG Bridge looking up each user's identity at query time to filter results. The permission promise 'holds only if the platform knows who its users actually are': identity must be federated from Active Directory, LDAP, or SSO into Keycloak, and users without POSIX UID and GID attributes fall back to a shared default identity that doesn't reflect file-level permissions. The Data Catalog (scored at 1A) is the other discovery surface, indexing metadata rather than content. The full stack is Keycloak identity, NVIDIA NeMo Retriever (NIMs, Milvus, the ingestion pipeline), observability, and an Envoy gateway, on a Kubernetes cluster running the App Store, the WEKA Operator, the CSI driver, and the NVIDIA GPU Operator, with an S3 bucket on NeuralMesh for the vector database and twelve RTX PRO 6000 GPUs across three nodes. The buyer gets permission-aware retrieval over its filesystem without building the pipeline.

The architect's concern is whose engine this is, how it's fronted, and what it assumes about identity. The embedders and retriever are NVIDIA's, the index is Milvus, the gateway serves plain HTTP on port 80 with no TLS out of the box, the GPU bill is twelve of NVIDIA's best, and WEKA's own contribution is the watcher, the operator, the identity wiring, and a permission model that's only as good as the enterprise's directory federation and UID and GID mapping.

Calibration: NetApp reads moderate on storage-integrated vectorization and RAG endpoints in its AI Data Engine; Everpure moderate on a single-node RAG appliance; Dell moderate on an Elastic-powered search engine; VAST strong on native vector search and permission-aware retrieval of its own; Nutanix moderate on layered retrieval (Milvus, NVIDIA AIDP) over its storage. WEKA is Nutanix's and NetApp's shape: NVIDIA's retrieval stack packaged over WEKA's storage, with WEKA's permission enforcement as the differentiator. Moderate.

**Borrowed Judgment:** Ceded at the package, with open and NVIDIA parts inside. AIDP's watchers, operator, Space Manager, identity wiring, and permission enforcement are WEKA's: Ceded. The NIM embedding and retrieval microservices are NVIDIA's on an NVIDIA license: Ceded to NVIDIA under the channel-substitution rule, the SUSE and Dataiku NIM reading; the vectors they make are the model's under the carve-out. Milvus is Apache 2.0 and would lift on its own, but here it's the platform's internal store fed by NVIDIA's embedders, so it doesn't earn a chip. The runtime call is the platform retrieving and answering per the permissions it captured at ingest, with no per-query override documented in the installation guide: vendor decides, visible (the GUI, Attu, observability), not overridable, Ceded, the NetApp AI Data Engine reading.

### ◑ Layer 1C · Pipelines: Data Movement & Pipelines

*Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering*  
**Status:** Object-Store Tiering and Snap-to-Object for Cost-Aware Movement, AIDP's Continuous Ingest as a Fixed Pipeline; the Augmented Memory Grid's KV Cache Tiering Is Commercially Available but Undocumented; NeuralMesh 6 Replication Pending

**Decision authority:** Delegated (decides: vendor; visible: true; overridable: true; boundary: vendor)

**Object-Store Tiering and Snap-to-Object (Any S3-Compatible Store Attached per Filesystem; Tiering Cue and Retention Policies per Filesystem Group; Per-Path Fetch and Release Overrides; Pre-Fetch; Snapshots to Object Storage for Backup, Disaster Recovery, and Cloud Bursting With Encrypted Keys)** [DAPM: Ceded]  
WEKA's tiering and snapshot mechanisms between its hot tier and the object store the enterprise chose. Ceded, the NetApp FabricPool and SnapMirror reading.

**AIDP Continuous Ingest as a Pipeline (Facet at 1C: Snapshot-Diff Change Capture, Parsing, Chunking, Embedding, Indexing; Fixed Stages on NVIDIA's Blueprint)** [DAPM: Ceded]  
The pipeline function of the AI Data Platform, scored here for what it moves; the index it feeds is the 1B chip. WEKA's watcher and operator around NVIDIA's stages: Ceded.

**Gap Analysis:** WEKA moves data between tiers and sites, and its most-talked-about mover is the one it hasn't documented. Tiering: every NeuralMesh filesystem can attach an object store (any S3-compatible store, on premises or in the cloud) and tier data from the NVMe hot tier by time-based policies set per filesystem group (a tiering cue and a drive retention period), with per-path manual overrides ('weka fs tier fetch' pulls files back to SSD, 'weka fs tier release' forces them out 'overriding standard retention policies', and the obs_direct mount mode bypasses retention), and snapshot to object storage (Snap-to-Object) for backup, disaster recovery, and cloud bursting, with encrypted filesystem keys traveling with the snapshot. Pipelines: AIDP's ingest is a fixed pipeline from a filesystem change, captured by snapshot-diff, through parsing, chunking, and embedding into a vector index, scored here for what it moves. The Augmented Memory Grid ('commercially available today on NeuralMesh and OCI', November 18, 2025; validated on OCI H100 infrastructure at '1000x more KV cache capacity' and '20x faster time to first token') keeps inference key-value caches in a persistent NVMe token warehouse and streams them back to GPUs, which is the cache tiering the layer's purpose line names, but it has no page in the 5.1 documentation index, so it's named, not scored. NeuralMesh 6 (second half of 2026) adds 'intelligent data mobility with replication and remote caching support'. The buyer gets its cold data on cheaper storage and its snapshots somewhere else, and a pipeline that keeps a vector index current.

The architect's concern is fixity and the documentation gap. Tiering is a policy, not a pipeline; AIDP's stages are NVIDIA's blueprint; cross-site replication is a future release; and the flagship KV cache feature is a press release, a product page, and open-source plugins without a documentation page behind them.

Calibration: NetApp reads moderate on a fixed AI-ingest pipeline plus SnapMirror, FlexCache, and FabricPool tiering; Everpure moderate on fleet replication plus a fixed preparation pipeline; Dell moderate on a data orchestration engine; VAST strong on a general DataEngine with user functions; Confluent and Cloudera strong on movement platforms. WEKA is NetApp's shape with the replication half pending. Moderate.

**Borrowed Judgment:** Ceded at every mover, Delegated on the override. Tiering, Snap-to-Object, and the AIDP pipeline are WEKA's mechanisms (the pipeline's stages NVIDIA's): Ceded, the NetApp FabricPool and SnapMirror reading; the object store behind them is the enterprise's choice and is scored on its owner's row. The runtime call is NeuralMesh tiering per the filesystem group's policy, and the documentation gives the enterprise a per-path reversal of that call (fetch, release, obs_direct): vendor decides, visible, overridable per path, Delegated under the override rule, the Snowflake and Cloudera reading; the tiering policy itself is configuration, the manual release is the override.

### ◑ Layer 2A · Orchestration: Infrastructure Orchestration

*GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization*  
**Status:** The WEKA Operator and Cloud Deployment Manager Run NeuralMesh on the Enterprise's Kubernetes and Clouds (Custom Resources, Rolling Upgrades, Auto-Scaling Groups, Composable Tenants); a Standard CSI Door; Node Selectors and Tolerations Pin Where WEKA Runs; No Compute or GPU Scheduling

**Decision authority:** Delegated (decides: vendor; visible: true; overridable: true; boundary: vendor)

**WEKA Operator (WekaCluster, WekaClient, WekaContainer, WekaPolicy; nodeSelector, roleNodeSelector, and Tolerations; Expansion and Shrink; Rolling Upgrades; Composable Clusters; Prometheus Metrics; x86 Only; EKS, OKE, GKE, AKS) + Cloud Deployment Manager and Terraform Modules for AWS, Azure, and GCP + the WEKA App Store (Helm Chart, GUI, and Operator for Deploying Applications Onto the Cluster)** [DAPM: Ceded]  
WEKA's control plane for WEKA's storage on the enterprise's Kubernetes and clouds, and its application deployment surface. Ceded, the NetApp Console and VAST Polaris reading.

**WEKA CSI Plugin (Open Source; Directory-, Snapshot-, and Filesystem-Backed Volumes; Quota Enforcement; Topology-Aware Provisioning; Snapshots and Cloning; WEKA Client or NFS Transport)** [DAPM: Delegated]  
A standard Kubernetes storage interface in front of WEKA volumes; the claims and classes lift to any CSI driver. Delegated, the NetApp Trident and Dell CSI Operator reading.

**Gap Analysis:** WEKA orchestrates its own storage on the enterprise's orchestrators. The WEKA Operator (its own release cadence, x86 only; Kubernetes 1.25 and OpenShift 4.17 minimums; EKS, OKE, GKE, and AKS supported with per-provider limits) manages WekaCluster, WekaClient, WekaContainer, and WekaPolicy custom resources with nodeSelector, roleNodeSelector, and tolerations that pin which nodes run which WEKA containers: cluster creation and expansion ('The number of containers cannot exceed available Kubernetes nodes'), shrinking with a hot spare, rolling, manual, or all-at-once upgrades, drive signing by policy, a 24-hour graceful destroy window, Composable Clusters per tenant, and, since Operator 1.7.0, an embedded CSI plugin, an automatic StorageClass, and Prometheus metrics by default. The Cloud Deployment Manager at cloud.weka.io is a wizard that generates the operator commands, Helm values, and manifests for dedicated, Axon, or Composable deployments, and the Terraform modules for AWS, Azure, GCP, and OCI create the instances, auto-scaling groups, and functions that install NeuralMesh in the enterprise's accounts. The CSI plugin (an open-source project on GitHub) provisions directory-, snapshot-, or filesystem-backed volumes with quota enforcement, topology-aware placement, expansion, snapshots, and cloning, over the WEKA client or, since 2.5.0, NFS transport; WEKA recommends the Operator-managed client over the stateless client it once documented. The WEKA App Store (a Helm chart on GitHub Pages) installs the Operator, the CSI driver, and a GUI for deploying AI applications onto the cluster. The buyer gets storage that follows its Kubernetes and its clouds declaratively.

The architect's concern is that nothing here schedules compute. The Operator places storage containers, the Terraform places storage instances, and the GPU, node, job, and fair-share decisions belong to the enterprise's Kubernetes, Slurm, or NVIDIA's software; the Operator's only template is 'dynamic' ('Future templates will include capacity and performance'); SMB-W needs Operator 1.11 with 5.1.20, Data Services 1.13 with 5.1.20 for quota coloring and 'Not supported for Data Catalog'.

Calibration: NetApp reads moderate on a data-infrastructure control plane plus an open CSI driver; VAST moderate on Polaris; Everpure moderate on Fusion plus Portworx; Nutanix strong on Prism, ADS, and a Kubernetes platform; CoreWeave strong on GPU orchestration. WEKA is NetApp's shape with a deeper Kubernetes operator. Moderate.

**Borrowed Judgment:** Ceded at the operator, Delegated at the pin and the CSI door. The WEKA Operator, the Cloud Deployment Manager, the Terraform modules, and the App Store are WEKA's: Ceded; the Kubernetes and clouds under them are the enterprise's and scored on their rows. The CSI plugin speaks the Kubernetes CSI standard in front of WEKA volumes and is open source: Delegated at that interface, the NetApp Trident reading. The runtime call the layer asks about is placement, and here the enterprise pins it: nodeSelector, roleNodeSelector, and tolerations on WekaCluster and WekaClient name the nodes WEKA containers run on, the Dataiku named-cluster reading under the override rule; the Operator schedules inside those pins. Vendor decides the defaults, visible (Prometheus, NeuralMesh Observe), overridable per node selection, Delegated. The Hugging Face and Everpure line (a hosted flavor is a menu, not a pin) doesn't apply to node selectors on the enterprise's own cluster.

### ◑ Layer 2B · Runtime: Application Runtime & Execution

*Model serving, agent execution, inference APIs, distributed inference*  
**Status:** The AI Data Platform's Agentic RAG API: NVIDIA NIM Inference Services, a RAG Server, and WEKA's RAG Gateway and RAG Bridge Answering Over the Platform's Own Index; No General Serving, No Agent Runtime; the Augmented Memory Grid Feeds Other Engines

**Decision authority:** Ceded (decides: model; visible: true; overridable: false; boundary: model)

**AI Data Platform Agentic RAG (NVIDIA RAG Blueprint: NIM Inference Services and RAG Server; WEKA RAG Gateway, RAG Bridge, and Space Manager; Answers Over the Platform's Own Index Under the User's File Permissions; UI and API; Prompt and Completion Traces in Phoenix)** [DAPM: Ceded]  
WEKA's gateway and bridge over NVIDIA's blueprint, answering only over what the platform indexed. Ceded to WEKA for the surface and to NVIDIA for NIM under the channel-substitution rule.

**Gap Analysis:** WEKA serves one thing: answers over what the AI Data Platform indexed. The App Store deploys the 'nvidia-rag-blueprint' ('All NIM inference services, the ingestion pipeline, and the RAG server') beside the 'aidp' components ('the AI Data Platform's GUI, Operator, RAG Gateway, RAG Bridge, and Space Manager') and 'aidp-observability' ('Logs, traces, and LLM prompt and completion visibility'); users and applications 'connect to NeuralMesh AIDP through a standard UI and API to run semantic queries' and get 'agentic RAG' answers, the RAG Gateway and RAG Bridge filtering by each user's file permissions at query time; the models are NVIDIA NIMs on the platform's twelve GPUs, and the product page's own division of labor is that AIDP 'handles the data layer ... while your inference layer focuses on what it does best'. The Augmented Memory Grid is memory for inference engines the enterprise runs (vLLM, TensorRT-LLM, Dynamo) and is named at 1C. The buyer gets a permission-aware RAG endpoint over its files, and nothing that serves a model of its choosing.

The architect's concern is that this is an appliance's answer, not a serving platform: no model catalog, no bring-your-own model, no agent runtime, a fixed NVIDIA blueprint behind WEKA's gateway, and the generative step's API isn't documented beyond 'a browser UI or API'.

Calibration: NetApp reads gap because its AI Data Engine retrieves without generating and the runtime is NVIDIA's; Everpure moderate on Data Stream's documented on-appliance chat endpoint; Nutanix moderate on platform-native serving; Dell moderate on blueprints plus services; VAST strong on AgentEngine. WEKA is Everpure's shape with less of its own inside: WEKA's gateway and bridge over NVIDIA's blueprint. Moderate on rule 4 (fixed-function), ruled September 15, 2026 with Everpure's 2B: NVIDIA's blueprint counts on WEKA's paper under the whose-paper rule, and a captive-destination answerer is a slice, not a gap; gap had been the first draft's reading.

**Borrowed Judgment:** Ceded at the answer. AIDP's RAG Gateway, RAG Bridge, and Space Manager are WEKA's; the NIM inference services and RAG server are NVIDIA's blueprint on an NVIDIA license: Ceded to WEKA for the surface and to NVIDIA for the models under the channel-substitution rule; the enterprise can't point the endpoint at another model or another index. The decision to answer is NVIDIA's model over the platform's retrieval, with no model swap and no pre-effect gate documented: model decides, visible (prompt and completion traces in Phoenix), not overridable, Ceded, the NetApp and Everpure reading.

### ○ Layer 2C · Reasoning: Agentic Infrastructure — The Reasoning Plane

*Policy-driven placement and resource coordination — the Autonomy Layer*  
**Status:** Tenant Isolation and Permission-Aware Retrieval Govern Data, Not Agents; Keycloak Inside AIDP Identifies Users; Not a Plane

**Decision authority:** Absent (decides: absent; visible: n/a; overridable: n/a; boundary: vendor)

**Gap Analysis:** Read against the five legs, WEKA has none as a plane over agents. Identity: Organizations, Composable Clusters, S3 STS and OIDC credentials, and AIDP's Keycloak identify tenants, users, and service principals to storage and to one application; no agent principal exists. Gateway: AIDP's RAG Gateway and RAG Bridge sit between a user or application and the platform's index, looking up the caller's identity at query time and filtering results by file permissions, and its observability records prompts and completions; that's an application-scoped retrieval gateway over one platform's data, scored with the platform at 1B and 2B, and nothing sits in front of an agent's model or tool calls in general. Registry and orchestration: none. Observability: WEKA Home, Prometheus metrics, and the S3 audit webhook watch storage; AIDP's observability watches the platform. What WEKA gives the reasoning plane is a governed substrate: permission-aware retrieval that enforces the filesystem's ACLs on vectors at query time, prompt and completion traces inside one application, hardware-isolated tenants, and an audit trail for storage actions.

The architect's concern is the same as NetApp's: data guardrails aren't agent governance.

Calibration: NetApp, VAST, Dell, and Everpure read gap; HPE moderate on an IT-operations reasoning plane; Nutanix moderate on an agent gateway. WEKA is NetApp's shape with an application-scoped gateway. Gap, authority Absent (ruled September 15, 2026): the 2C floor is the Nutanix line, a GA gateway every agent and model call passes through with governance and audit over the enterprise's agent traffic; AIDP's RAG Gateway, RAG Bridge, Keycloak identity, and Phoenix traces are one application's own governance over one platform's data (the Cloudera Agent Studio and Confluent reading), and a permission filter isn't reasoning. Both reviewer passes had voted moderate.

**Borrowed Judgment:** Nothing offered as a plane over agents. The enterprise that wants agent identity, a gateway, a registry, or orchestration brings its own; WEKA's permissions travel with the data, not with the agent. Absent.

### ○ Layer 3 (+1) · Applications: AI Application Layer — The Value Plane

*AI-powered business capabilities — business logic, workflow automation*  
**Status:** No Application: the App Store Deploys One Documented Blueprint, the AI Data Platform, Which Is a Data Pipeline; the Catalogue's Breadth Is Undocumented

**Decision authority:** Absent (decides: absent; visible: n/a; overridable: n/a; boundary: vendor)

**Gap Analysis:** WEKA ships no application. The WEKA App Store ('browsing and deploying AI applications' from a Helm chart, with a blueprints catalogue, a credential manager, and a compatibility check) is deployment tooling scored at 2A, and the only blueprint its documentation covers is the AI Data Platform, which WEKA's own page calls 'WEKA's AI data pipeline' and which is scored at 1B, 1C, and 2B; the catalogue's other contents aren't documented, and WEKA's software partners page lists reference architectures, not deployable applications. The buyer gets nothing to log into at this layer.

The architect's concern is nil: there's no application to be captured by.

Calibration: NetApp and Everpure (escalated) read gap on storage beneath others' applications; Nutanix moderate on a documented ISV catalogue; VAST moderate on a focused ecosystem; Dell and HPE partner on formal programs. The first draft read moderate on the Nutanix reading; the ChatGPT pass showed the documented catalogue is one data pipeline. Gap, authority Absent.

**Borrowed Judgment:** Nothing offered, nothing inherited. Absent.

---
*Layer2C · AI Infrastructure Decision Intelligence · The CTO Advisor LLC (DBA The Advisor Bench) · thectoadvisor.com*
