惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Tailwind CSS Blog
大猫的无限游戏
大猫的无限游戏
L
LINUX DO - 热门话题
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
雷峰网
雷峰网
aimingoo的专栏
aimingoo的专栏
博客园_首页
MongoDB | Blog
MongoDB | Blog
V
V2EX
GbyAI
GbyAI
量子位
Microsoft Azure Blog
Microsoft Azure Blog
有赞技术团队
有赞技术团队
G
Google Developers Blog
云风的 BLOG
云风的 BLOG
B
Blog
Microsoft Security Blog
Microsoft Security Blog
S
SegmentFault 最新的问题
O
OpenAI News
N
News and Events Feed by Topic
博客园 - Franky
爱范儿
爱范儿
Forbes - Security
Forbes - Security
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
V2EX - 技术
V2EX - 技术
Application and Cybersecurity Blog
Application and Cybersecurity Blog
N
News and Events Feed by Topic
N
News | PayPal Newsroom
Schneier on Security
Schneier on Security
Cloudbric
Cloudbric
Security Archives - TechRepublic
Security Archives - TechRepublic
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Recent Commits to openclaw:main
Recent Commits to openclaw:main
人人都是产品经理
人人都是产品经理
P
Privacy International News Feed
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog RSS Feed
阮一峰的网络日志
阮一峰的网络日志
D
DataBreaches.Net
Last Week in AI
Last Week in AI
罗磊的独立博客
Spread Privacy
Spread Privacy
Recent Announcements
Recent Announcements
The Cloudflare Blog
Google DeepMind News
Google DeepMind News
AWS News Blog
AWS News Blog
The Register - Security
The Register - Security
Y
Y Combinator Blog
J
Java Code Geeks
I
Intezer

Pinecone

Pinecone Assistant: A Managed Knowledge Layer for Production AI Applications Multi-domain RAG in n8n: why one knowledge base is not enough Allspice Transforms the Culinary Experience with Semantic Search Powered by Pinecone | Pinecone Building RAG workflows in n8n: choosing the right Pinecone node Knowledge needs a meta-knowledge layer Garbage Day: How Pinecone Safely Deletes Billions of Objects at Scale When "Performance" Means Two Different Things True, Relevant, and Wrong: The Applicability Problem in RAG Use the Pinecone Plugin for Claude Code to develop AI Applications Faster Millions at Stake: How Melange's High-Recall Retrieval Prevents Litigation Collapse Powering High-stakes Patent Search at Scale: How Melange Built a Reliable AI System on Pinecone | Pinecone Pinecone Assistant Node in n8n: Turn Any Data Source Into Knowledge RAG with Access Control Pinecone Dedicated Read Nodes are now in Public Preview Inside Pinecone: Slab Architecture New Bulk Data Operations: Update, Delete, and Fetch by Metadata The Hidden Cost of Building: Lessons from Aquant Simplifying Vector Embeddings with Pinecone Integrated Inference Capabilities Pinecone joins Microsoft Marketplace as a Launch Partner GTM Engineering: Clay + Pinecone for AI-powered Sales Outbound Build an AI knowledge assistant with Google Docs and Pinecone Moving Pinecone forward with Ash Ashutosh as CEO and Edo spearheading our growing AI ambitions as Chief Scientist Pinecone Founder Edo Liberty to Spearhead Pinecone’s Growing AI Ambitions; Appoints Ash Ashutosh as CEO to Expand Vector Database Market Leadership Fast, Accurate Retrieval for Creators at Scale: Delphi’s Path Toward a Million Conversational Agents with Pinecone | Pinecone Announcing Pinecone Pioneers: A Program for Builders, Organizers, and Community Leaders What is Context Engineering? Chunking Strategies for LLM Applications Beyond the hype: Why RAG remains essential for modern AI Obviant Makes 30% More Accurate Defense Acquisition Recommendations Combining Sparse and Dense Retrieval with Pinecone | Pinecone Build more knowledgeable AI applications with new LLMs and greater control in Pinecone Assistant #NYTECHWEEK 2025 Retrieval-Augmented Generation (RAG) Accurate and Efficient Metadata Filtering in Pinecone’s Serverless Vector Database | Pinecone Terminal X AI Agents, Powered by Pinecone, Turn Complex Financial Data Into Production-grade Insights at Scale | Pinecone Aquant Delivers Scalable, Expert-level Service Intelligence with Pinecone | Pinecone Cascading retrieval with multi-vector representations: balancing efficiency and effectiveness Vector databases aren't just for large-scale enterprise AI Unveiling DIME: Reproducibility, Scalability, and Formal Analysis of Dimension Importance Estimation for Dense Retrieval | Pinecone Fast and Effective Early Termination for Simple Ranking Functions | Pinecone Domain-specific AI Agents at Scale: CustomGPT.ai Serves 10,000+ Customers with Pinecone | Pinecone Using Pinecone asynchronously with FastAPI A Flexible Resource for Top-Weighted Comparisons Between Sets and Rankings | Pinecone Build secure, scalable agentic AI workflows with Rubrik Annapurna and Pinecone Tool up: Pinecone’s first MCP servers are here Add context to your agent with Pinecone Assistant MCP remote server E2Rank: Efficient and Effective Layer-wise Reranking | Pinecone ColBERT-serve: Efficient Multi-Stage Memory-Mapped Scoring | Pinecone Efficient Constant-Space Multi-Vector Retrieval | Pinecone How Vanguard Worked with Pinecone to Boost Customer Support with Faster Calls and 12% More Accurate Responses | Pinecone Pinecone Named to Fast Company's Annual List of the World's Most Innovative Companies of 2025 Launch Week: Pinecone for agents, search, recommendations, and more Optimizing Pinecone for agents (and more) Retrieval Inference for scale and performance How 1up Turns Sales Reps Into Product Experts with Pinecone | Pinecone Don’t be dense: Launching sparse indexes in Pinecone Unlock High-Precision Keyword Search with pinecone-sparse-english-v0 Evolving Pinecone's architecture to meet the demands of Knowledgeable AI Pinpoint references faster with citation highlights in Pinecone Assistant Bringing the leading vector database to your cloud Getting started with llama-text-embed-v2 Natural Language Counterfactual Explanations for Graphs Using Large Language Models | Pinecone Easily build knowledgeable chat and agent-based applications in minutes with Pinecone Assistant, now generally available How to build an agentic, chat or RAG knowledge system using Pinecone Assistant Real-time RAG with Pinecone and Estuary Flow BigQuery to Pinecone in Real-Time with Estuary Flow Stravito Turns Market and Consumer Data Into Actionable Insights with Pinecone Inference | Pinecone Accelerate prototyping and development with Pinecone Local First-of-its-kind Pinecone Knowledge Platform to Power Best-in-class Retrieval for Customers Introducing integrated inference: Embed, rerank, and retrieve your data with a single API Strengthening security and increasing control with CMEK and API key roles Introducing Pinecone Rerank V0 Introducing cascading retrieval: Unifying dense and sparse with reranking From Idea to Action: How Pinecone Assistant Meaningfully Accelerates AI Business Building AI apps on Azure with Pinecone just got a lot easier Building a reliable, curated, and accurate RAG system with Cleanlab and Pinecone Four features of the Assistant API you aren't using - but should Deploying Pinecone with Infrastructure as Code (IaC) Streamlining CI/CD with Pinecone Local September 2024 Product Update Results of the Big ANN: NeurIPS'23 competition | Pinecone Introducing import from object storage for more efficient data transfer to Pinecone serverless Simplify, enhance, and evaluate RAG development with Pinecone Assistant, now in public preview Vectors and Graphs: Better Together August 2024 Product Update Pinecone Helps Deep Talk Deliver World-Class AI Assistants with Lower Engineering Overhead | Pinecone Assembled Delivers Better, Faster AI- Driven Support with Pinecone | Pinecone Llama 3.1 Agent using LangGraph and Ollama Build knowledgeable AI with Pinecone serverless, now generally available on Microsoft Azure Pinecone serverless is now generally available on Google Cloud, adding knowledge to AI assistants and other applications Accelerating Legal Discovery and Analysis with Pinecone and Voyage AI Bridging Dense and Sparse Maximum Inner Product Search | Pinecone Refine Retrieval Quality with Pinecone Rerank Introducing reranking to Pinecone Inference to simplify building accurate AI July 2024 Product Update Connect to Pinecone within your platform to enable a seamless AI development experience Introducing Pinecone API Versioning RAG Brag with Inkeep Co-Founder Nick Gomez LangGraph and Research Agents Introducing Pinecone Inference to streamline your AI workflow Build Privacy-aware AI software using Pinecone
Pinecone BYOC: Pinecone in your AWS, GCP, or Azure account, no vendor access
Gavin Johnson · 2026-02-20 · via Pinecone

If you’re taking search, recommendations, or agents to production, you eventually hit the same checkpoint: security review.

When security blocks the knowledge layer, it slows everything down. Teams stay in pilot mode. Ownership gets muddy. “Quick fixes” like bolt-on stacks or partial self-hosting often create new problems, like higher operational burden and a bigger access surface area.

The cost shows up fast. Every week you’re stuck in security review is a week your AI features aren’t in production.

The blocker isn’t performance or features. It’s a single security requirement: no vendor access into your cloud account or cluster. What you need is a path to production that clears that bar without changing your delivery plan.

Pinecone Bring Your Own Cloud (BYOC), available now in public preview for all Enterprise users, brings Pinecone into your AWS, GCP, or Azure account with a zero-access operating model.

With BYOC, the Pinecone Database’s data plane runs inside your VPC. Your vectors are stored and queried there. Pinecone doesn’t need SSH, VPN, or inbound network access to your cloud account, VPC, Kubernetes cluster, nodes, or workloads. You don’t open inbound firewall ports for Pinecone to operate the system.

You still use the Pinecone control plane (API and console) for index lifecycle, auth, and usage visibility.

TL;DR

With BYOC, you get:

  • Data plane in your cloud account: Vectors are stored and queried inside your VPC.
  • Zero-access operations: Pinecone doesn’t need SSH, VPN, or inbound access paths into your VPC or cluster.
  • Outbound-only operations: Components in your cluster pull queued operations over TLS and execute them locally.
  • Auditable operations: Operations are represented as Kubernetes custom resources, so you can see what ran and when.
  • Monitoring without data exposure: Only operational metrics and traces are sent. Your vectors, record metadata, and request payloads stay in your cloud account.
  • Public or AWS PrivateLink/GCP PSC/Azure Private Link-only connectivity: Choose a public endpoint or disable public access and connect via AWS PrivateLink, GCP Private Service Connect (GCP PSC), or Azure Private Link.
  • Same control plane workflow: Create, list, and delete indexes through the Pinecone API and console.

BYOC architecture diagram

What is BYOC?

BYOC delivers uncompromising governance and safety for teams with the strictest requirements.

BYOC is Pinecone’s split-plane architecture applied to a zero-access enterprise security posture:

  • Control plane (managed by Pinecone): Index lifecycle, authentication, user management, billing, and usage visibility. The control plane does not store or process your vectors.
  • Data plane (hosted by you): Vector storage and query execution inside a dedicated VPC in your cloud account.

This keeps your data plane inside your security boundary while preserving the control plane experience your teams already use.

Why teams choose BYOC

When the point is to ship production AI without getting stuck in security review, “keep data in our cloud” is often not enough. The real requirement is usually: no external access paths into production, even for operations.

The usual options create costly failure modes:

  • Managed service with vendor access: Faster to start, but can stall in security review and expand your third-party access surface area.
  • Fully self-hosted: Clears the access line, but shifts reliability, upgrades, and incident response entirely onto your team.

BYOC combines managed operations with data plane isolation. You keep the data plane inside your cloud account. Operations execute inside your cluster. Pinecone does not need direct access to your infrastructure.

  • Enterprise governance and safety: Vectors and query execution stay inside your cloud boundary. Operations are auditable, and responsibilities are clear.
  • Faster path to production: You can meet strict access requirements without switching to a fully self-hosted model.
  • Operational consistency: You keep the control plane workflow your teams already use, without introducing direct access paths into your infrastructure.

BYOC’s zero-access security model

BYOC is designed around a zero-access boundary. Pinecone does not need interactive access to your infrastructure to operate the data plane.

Zero-access means

  • Pinecone does not need SSH, VPN, or inbound access to your cluster.
  • You control cloud account boundaries, networking, and Kubernetes access.
  • Operational changes run through explicit, software-mediated workflows.

Zero-access does not mean

  • You lose the Pinecone control plane. You still use the API and console for index lifecycle, auth, and visibility.
  • You do everything manually. Operations are still orchestrated through the control plane. Your cluster executes them locally.
  • You have no support from Pinecone. We don’t have access to your cloud account or infrastructure, but we have visibility into your BYOC deployment via metrics and traces and are on-call for support.

How it works without direct access

BYOC separates control plane operations from data plane requests.

Control plane operations

Control plane operations – upgrades, scaling, maintenance, etc. – are queued by Pinecone and executed inside your environment using an outbound-only, pull-based model.

  1. Your Pinecone admin initiates a cluster operation (scale, upgrade, restart, etc.).
  2. The control plane queues operations for your environment.
  3. Components in your cluster pull pending operations and execute them locally.
  4. Your cluster reports health and state back to the control plane.

Data plane requests

Data plane requests are things your apps do every day: upsert, query, fetch, and other index operations. These requests go directly from your clients to the data plane running in your VPC.

  • Your apps connect to the BYOC index endpoint.
  • Requests are served by the data plane inside your account.
  • Pinecone doesn't need network access into your VPC to serve data plane traffic.

Monitoring

For monitoring and support, the cluster sends operational metrics and traces to Pinecone’s observability stack – never vectors, record metadata, and request payloads.

The key point: control plane operations are pulled outbound, and data plane requests are served inside your VPC.

What leaves your cloud account (and what doesn’t)

Does not leave your cloud account:

  • Vectors, metadata, and index contents.
  • Query and upsert payloads.
  • Customer data.

Can leave your cloud account:

  • Operational metrics and traces (for example, CPU, memory, latency).
  • Cluster health and operation status.

Deployment model

BYOC is deployed using a self-serve kit that fits standard platform workflows.

A typical rollout looks like this:

  1. Start in a non-production AWS, GCP, or Azure account that matches your production network and policy controls.
  2. Deploy with the BYOC self-serve kit and integrate it into CI/CD or GitOps flow.
  3. Promote the same deployment model to production.

The BYOC deployment step looks like this:

  1. Run an interactive setup wizard. It checks prerequisites and validates AWS/GCP/Azure quotas.
  2. The wizard generates a Pulumi project for your environment.
  3. You deploy into your cloud with pulumi up.

See the BYOC GitHub repository and documentation for more information.

Provisioning creates the data plane environment in your cloud account, including a dedicated VPC and an EKS/GKE/AKS cluster, plus supporting cloud services for storage, system state, and TLS/DNS.

Private connectivity options

You can choose the network posture that matches your environment:

  • Public access enabled: connect using the standard index host URL.
  • Public access disabled: connect only from within your VPC using AWS PrivateLink, GCP PSC, or Azure Private Link and the private host URL.

Control plane operations still work in either mode.

What’s available today

BYOC is available on AWS, GCP, and Azure for Enterprise users in public preview. In this release, BYOC supports:

  • Single-namespace Dedicated Read Nodes (DRN) indexes
  • Split control plane/data plane architecture
  • Pull-based operations and upgrades
  • Operational telemetry for monitoring
  • Network access modes: public or AWS PrivateLink/GCP PSC/Azure Private Link-only
  • Compatible with the Pinecone CLI

Some Pinecone capabilities that depend on Pinecone-hosted services outside your cloud account are not yet available in BYOC, such as:

See the BYOC documentation for more information.

Getting started

BYOC lets you meet the strictest security requirements without giving up managed infrastructure or slowing your path to production. BYOC is self-serve for Enterprise users in public preview. To deploy, start with the setup wizard in the BYOC GitHub repo, then follow the BYOC documentation. If you have any questions or need any assistance, contact your account team or send a request through our contact us form.