Skip to content

NVIDIA BlueField

NVIDIA BlueField is a family of data processing units (DPUs) that sit in servers and storage systems and run networking, storage and security services on their own processors and accelerators, so host CPUs and GPUs are left for application work.1

Also known as BlueField DPU, BlueField-3, BlueField-4, BlueField-4 STX, Vera BlueField-4 STX, Data processing unit (DPU)

At a glance

What is it?
BlueField is NVIDIA's family of infrastructure processors. Each device combines processor cores, high-speed networking and hardware accelerators for networking, storage and security. The current members are BlueField-3, a 400 Gb/s DPU, and BlueField-4, an 800 Gb/s DPU that combines an NVIDIA Grace CPU with ConnectX-9 networking. A storage variant, the BlueField-4 STX storage processor, pairs the NVIDIA Vera CPU with ConnectX-9 for storage systems. Software for BlueField is written with NVIDIA DOCA, the SDK and runtime that also covers ConnectX network adapters.12
What does it do?
BlueField takes infrastructure work off the host. It handles software-defined networking and routing, storage access over RDMA, NVMe over Fabrics and GPUDirect Storage with block, file and object support, and security functions such as isolation, threat detection and runtime protection. Because these services run on the DPU rather than on the host, a tenant's workload cannot easily tamper with them, which supports multi-tenant isolation. BlueField also acts as an infrastructure controller that integrates with Kubernetes for provisioning. BlueField-3 can additionally serve as a SuperNIC in Spectrum-X networks for Hopper-era systems.13
Who needs it?
Cloud and AI service providers that run many tenants on shared GPU infrastructure and need strong isolation; storage vendors building AI data platforms; security vendors that want to enforce policy below the host operating system; enterprises running on-premises AI factories; and operators of industrial control systems that want a dedicated security processor at the edge.12
What does it need?45
  • Servers or storage systems with a supported BlueField device (or Vera Rubin platforms for BlueField-4)
  • DOCA-Host on the server and the BlueField software bundle on the device
  • DOCA SDK and a Linux development environment for building custom services
  • A decision on the mode of operation (DPU, zero-trust or NIC)
  • Partner or DOCA services that will run on the DPU
What it is not
BlueField is not a GPU and does not run AI models for applications; it runs the infrastructure services around them. It is not a plug-and-play speed-up either: value comes from DOCA-based services and partner software running on it, and in our view an application with no such service gains little from the hardware alone. BlueField can operate in NIC mode, though we would not buy it only as a network card. BlueField-4 figures such as six times the compute of BlueField-3 are NVIDIA statements, and NVIDIA's October 2025 launch post planned an early-availability launch with Vera Rubin platforms in 2026. NVIDIA's May 31, 2026 release says Vera Rubin, which integrates BlueField-4 DPUs, is in full production with shipments starting in fall 2026. We recommend confirming BlueField-4 availability for a given server with its vendor.256

Availability and licensing. BlueField-3 is sold through partners and the NVIDIA Marketplace. NVIDIA's October 2025 launch post planned an early-availability launch of BlueField-4 with Vera Rubin platforms in 2026. NVIDIA's May 31, 2026 releases say Vera Rubin, which integrates BlueField-4 DPUs, is in full production with shipments starting in fall 2026, and that STX-based storage platforms are expected from partners in the second half of 2026. DOCA is provided under the DOCA EULA.156

The problem it solves

In modern data centers, a growing share of host CPU time goes to infrastructure tasks: virtual networking, storage protocols, encryption and security monitoring. That time is taken from applications, and because these services run on the same host as tenant workloads, a compromised workload can interfere with them.

BlueField moves those services to a separate processor on the network path. The host keeps its cycles for applications, and the infrastructure runs in a domain isolated from the tenant, which helps both performance and security in shared AI clusters.4

How it works

BlueField sits between the server or storage system and the network.

  • Hardware: processor cores (Grace in BlueField-4, Vera in BlueField-4 STX), networking up to 400 Gb/s (BlueField-3) or 800 Gb/s (BlueField-4) and accelerators for networking, storage, cryptography and security.
  • Runtime: the BlueField software bundle includes the bootloader, OS kernel, NIC firmware, drivers and Ubuntu 22.04 as the on-device Linux distribution; DOCA-Host is installed on the server.
  • Modes: DOCA documents DPU, zero-trust and NIC modes of operation.
  • Services: DOCA libraries and microservices (for example DOCA Flow, App Shield, storage emulation) and partner applications run on the device. Standard APIs such as DPDK, SPDK and Linux Netlink are supported.

In AI factories, the DOCA Platform Framework, part of DSX OS, orchestrates BlueField-accelerated infrastructure services.47

NVIDIA BlueField architecture: components by layer and how they connectApplications &solutionsOperations &orchestrationAcceleratedcomputingNetworking, power &facilitiesPartner security, storage and networking applications: Commercial services built on DOCAPartner security, storageand networking applicationsBlueField bundle and DOCA-Host: On-device OS, firmware and drivers; host-side driversBlueField bundle andDOCA-HostDOCA libraries and microservices: Networking, storage and security services on the DPUDOCA libraries andmicroservicesDOCA Platform Framework (DSX OS): Orchestrates BlueField services across the clusterDOCA Platform Framework (DSXOS)Host server or storage system (CPU and GPUs): Runs tenant applications and AI workloadsHost server or storagesystem (CPU and GPUs)BlueField DPU (BlueField-3, BlueField-4): Processor cores, networking and accelerators on the data pathBlueField DPU (BlueField-3,BlueField-4)BlueField-4 STX storage processor: Storage-side CPU and data-path engineBlueField-4 STX storageprocessorData center network (for example Spectrum-X): Network the DPU connects toData center network (forexample Spectrum-X)
Diagram as a list
  1. Applications & solutions

    • Partner security, storage and networking applicationsCommercial services built on DOCAConnects to DOCA libraries and microservices
  2. Operations & orchestration

    • BlueField bundle and DOCA-HostOn-device OS, firmware and drivers; host-side driversConnects to BlueField DPU (BlueField-3, BlueField-4)
    • DOCA libraries and microservicesNetworking, storage and security services on the DPUConnects to BlueField bundle and DOCA-Host
    • DOCA Platform Framework (DSX OS)Orchestrates BlueField services across the clusterConnects to DOCA libraries and microservices
  3. Accelerated computing

    • Host server or storage system (CPU and GPUs)Runs tenant applications and AI workloadsConnects to BlueField DPU (BlueField-3, BlueField-4)
  4. Networking, power & facilities

    • BlueField DPU (BlueField-3, BlueField-4)Processor cores, networking and accelerators on the data pathConnects to Data center network (for example Spectrum-X)
    • BlueField-4 STX storage processorStorage-side CPU and data-path engineConnects to Data center network (for example Spectrum-X)
    • Data center network (for example Spectrum-X)Network the DPU connects to
Components and connections as documented by NVIDIA.5

Capabilities

  • Accelerated networking1

    Up to 800 Gb/s connectivity with accelerations for software-defined networking and distributed routing, including integrated overlay and L3 underlay networking.

    Why it matters: Frees host CPU cores from virtual networking.

    Limits: 800 Gb/s applies to BlueField-4; BlueField-3 is 400 Gb/s.

  • In-silicon security4

    Zero-trust enforcement with real-time threat detection, isolation and runtime protection; DOCA adds inline cryptography and App Shield runtime security.

    Why it matters: Security controls run outside the host a tenant controls.

    Limits: Protection depends on the security services deployed on the DPU.

  • AI storage acceleration1

    RDMA, NVMe over Fabrics and GPUDirect Storage, with block, file and object support, plus storage emulation and compression in DOCA.

    Why it matters: Speeds data access for training and inference context.

    Limits: Requires storage software that uses these interfaces.

  • BlueField-4 STX storage processor18

    Combines the Vera CPU and ConnectX-9 as a storage-side CPU and data-path engine for access, metadata processing and secure storage services in the I/O path.

    Why it matters: Moves storage processing into the data path of AI storage systems.

    Limits: STX-based platforms are expected from partners in the second half of 2026; NVIDIA's throughput figures are vendor claims.

  • DOCA software platform4

    SDK and runtime with libraries for RDMA, networking, security, storage, data-path acceleration and management, plus industry-standard APIs such as DPDK and SPDK.

    Why it matters: One programming model across BlueField generations and ConnectX.

    Limits: Distributed under the DOCA SDK end-user license agreement.

  • Modes of operation5

    BlueField can run in DPU, zero-trust or NIC mode.

    Why it matters: The same hardware can serve different roles.

    Limits: Switching modes requires reconfiguration documented by DOCA.

  • Kubernetes integration and elastic provisioning1

    BlueField acts as an infrastructure controller with service function chaining and Kubernetes integration for rapid provisioning.

    Why it matters: Infrastructure services scale with the cluster.

    Limits: Orchestration relies on frameworks such as the DOCA Platform Framework.

Practical use cases

An AI cloud provider must isolate tenants on shared GPU servers without spending host CPU on virtual networking and security.
Approach
Run networking, storage and security services on BlueField so they are isolated from tenant workloads.
Role of NVIDIA BlueField
BlueField offloads and isolates infrastructure services.
Data, infrastructure and skills
DOCA services or partner software, a multi-tenant network design.
Type of benefit
Tenant isolation and host CPU offload
Caveats
Isolation strength depends on how services are configured.
First step
List the infrastructure services currently consuming host CPU.

Sources 1

A storage platform for AI cannot keep data moving fast enough for agents and inference context.
Approach
Build the storage system on BlueField-4 STX so data access, metadata and security run in the I/O path.
Role of NVIDIA BlueField
BlueField-4 STX acts as the storage-side processor.
Data, infrastructure and skills
A storage partner platform based on STX.
Type of benefit
Data path throughput for AI storage
Caveats
STX-based platforms are expected in the second half of 2026; vendor throughput figures need independent testing.
First step
Check which storage partners have announced STX-based platforms.

Sources 1

Industrial control systems need security monitoring without risking the availability of the process.
Approach
Use BlueField as a dedicated security processor within the operational system for visibility and zero-trust enforcement.
Role of NVIDIA BlueField
BlueField runs security functions apart from the controlled equipment.
Data, infrastructure and skills
OT security software that supports BlueField.
Type of benefit
Security monitoring without host impact
Caveats
Industrial certification depends on the full system, not the DPU alone.
First step
Review the OT security material linked from the BlueField page.

Sources 1

Who uses it

  • xAI · AI model development

    xAI Colossus: Spectrum-X Ethernet for a 100,000-GPU training cluster

    xAI's Colossus cluster in Memphis started with 100,000 NVIDIA Hopper GPUs, connected with NVIDIA Spectrum-X Ethernet (SN5600 switches and BlueField-3 SuperNICs) to train Grok models. NVIDIA reports 95 percent data throughput, compared with the 60 percent it attributes to standard Ethernet at this scale.

    In production

Works with

Complementary tools

  • NVIDIA DSXThe DOCA Platform Framework in DSX OS operates BlueField-accelerated infrastructure services.
  • NVIDIA OpenShellNVIDIA's Open Agent Safety Platform combines OpenShell with NVIDIA Sentry and BlueField-4 in-silicon enforcement.
  • NVIDIA Mission ControlPartner software listed on the Mission Control page (Netris) spans BlueField DPUs for tenant isolation.

Same family

Relationship labels follow NVIDIA's documentation. "Alternative approaches" does not mean one is better: each profile says when it fits.

Getting started

  1. Choose the device

    Compare BlueField-3 (400 Gb/s), BlueField-4 (800 Gb/s) and BlueField-4 STX using their datasheets against your throughput and platform needs.

    Check: A chosen device that matches your server platform and timeline.

  2. Install the runtime

    Download DOCA-Host and the BlueField bundle runtime image from the DOCA developer page.

    Check: The DPU boots its bundled OS and the host sees the device.

  3. Set the mode of operation

    Follow the DOCA BlueField Modes of Operation guide to select DPU, zero-trust or NIC mode.

    Check: The device reports the intended mode.

  4. Run a reference application

    Follow the DOCA Developer Quick Start Guide to build and run a reference application such as DMA Copy or the IPsec Security Gateway.

    Check: The reference application runs and passes traffic.

  5. Pick production services

    Decide which DOCA microservices or partner applications from the BlueField ecosystem will run in production.

    Check: Each service has an owner and a supported version.

Official resources

Could this technology help you?

Describe your project to the Solution Architect. It starts with NVIDIA BlueField as context but recommends independently, including when you do not need it.

Check it against my project

Sources

Each statement above links to the source it comes from. Labels say who reported it.

  1. NVIDIA BlueField Platform (opens in a new tab) NVIDIA · Vendor-reported · link checked 9 Oct 2026
  2. NVIDIA Launches BlueField-4 (28 Oct 2025) (opens in a new tab) NVIDIA Blog · Vendor-reported · link checked 9 Oct 2026
  3. NVIDIA Spectrum-X Ethernet Networking Platform (opens in a new tab) NVIDIA · Vendor-reported · link checked 9 Oct 2026
  4. NVIDIA DOCA Software Framework (opens in a new tab) NVIDIA · Vendor-reported · link checked 9 Oct 2026
  5. DOCA Documentation v3.5.0 (opens in a new tab) NVIDIA · Vendor-reported · link checked 9 Oct 2026
  6. NVIDIA newsroom: Vera Rubin ramps into full production (opens in a new tab) NVIDIA · Vendor-reported · link checked 9 Oct 2026
  7. NVIDIA DSX documentation (opens in a new tab) NVIDIA · Vendor-reported · link checked 9 Oct 2026
  8. NVIDIA Vera BlueField-4 STX Brings Agentic AI Storage Processing With In-Silicon Security (31 May 2026) (opens in a new tab) NVIDIA Newsroom · Vendor-reported · link checked 9 Oct 2026

Fill out the form below to request your copy.

Name(Required)