Storage considerations
To install IBM® Guardium Insights, you must have a supported file storage system on your Red Hat® OpenShift® cluster.
As you plan your system, remember that not all services support all types of storage. For complete information on the storage types supported by each service, see Storage requirements.
- What storage options are supported for the platform?
- What storage options are supported on my cloud deployment environment?
- What storage options are supported on the version of Red Hat OpenShift Container Platform that I am running?
- What storage options are supported on my hardware?
- License requirements
- Storage classes
- Data replication for high availability
- Backup and restore
- Encryption of data at rest
- Network and I/O requirements
- Resource requirements
- Guardium Insights configuration guidance
What storage options are supported for the platform?
Guardium Insights supports dynamic storage provisioning. A Red Hat OpenShift cluster administrator must properly configure storage before Guardium Insights is installed.
As you plan your system, remember that not all services support all types of storage. For complete information on the storage types supported by each service, see Storage requirements.
If the services that you want to install don't support the same type of storage, you can have a mixture of different storage types on your cluster.
Guardium Insights supports and is optimized for several types of persistent storage:
Storage option | Version | Notes |
---|---|---|
OpenShift Data Foundation (formerly called OpenShift Container Storage) | Version: 4.6 or later | Available in the IBM Storage Suite for IBM Cloud®
Ensure that you install a version of OpenShift Data Foundation that is compatible with the version of Red Hat OpenShift Container Platform that you are running. For details, see https://access.redhat.com/articles/4731161. |
OpenShift Data Foundation as a Service | Not applicable | Contact IBM Support for assistance. OpenShift Data Foundation as a Service is available as part of a special agreement between AWS and IBM Guardium Insights Product Managers. Contact the Product Management team for assistance. |
IBM Spectrum® Fusion | Version 2.2.0 or later fixes | Available in either:
|
IBM Spectrum Scale Container Native (with IBM Spectrum Scale Container Storage Interface) | Version 5.1.3.x or later fixes CSI Version 2.5.x or later fixes |
Available in either:
|
Portworx | Version 2.9.1 or later fixes | |
NFS | Version 3 or 4 The latest version is recommend. |
|
Amazon Elastic Block Store (EBS) | Not applicable | Your environment must also include EFS storage. |
Amazon Elastic File System (EFS) | Not applicable | It is recommended that you use both EBS and EFS storage. |
IBM Cloud Block Storage | Not applicable | Your environment must also include IBM Cloud File Storage. |
IBM Cloud File Storage | Not applicable | It is recommended that you use both IBM Cloud Block Storage and IBM Cloud File Storage storage. |
- Evaluate whether the storage on your cluster is sufficient for use with Guardium Insights.
- Assess storage provided by other vendors. This tool does not guarantee support for other types of storage. You can use other storage environments at your own risk.
What storage options are supported on my cloud deployment environment?
Some storage options are supported only on a specific deployment environment. Ensure that you select a storage option that works on your chosen cloud deployment environment.
For clusters hosted on third-party infrastructure, such as IBM Cloud or Amazon Web Services, it is recommended that you use storage that is native to the infrastructure, if possible.
Deployment environment | Managed OpenShift | Self-managed OpenShift |
---|---|---|
On-premises | IBM Cloud Satellite supports the following
storage options:
|
The following storage options are supported on bare metal and VMware infrastructure:
|
IBM Cloud | Red Hat
OpenShift on IBM Cloud supports the following
storage options:
|
The following storage options are supported on classic
IBM Cloud infrastructure:
The following storage options are supported on VPC IBM Cloud infrastructure:
|
Amazon Web Services (AWS) | Red Hat OpenShift Service on AWS (ROSA) supports the following storage options:
|
The following storage options are supported on AWS infrastructure:
|
Microsoft Azure | Azure Red Hat
OpenShift (ARO) supports the following storage options:
|
The following storage options are supported on Microsoft Azure infrastructure:
|
Google Cloud | Managed OpenShift on Google Cloud is not supported. | The following storage options are supported on Google Cloud infrastructure:
|
What storage options are supported on the version of Red Hat OpenShift Container Platform that I am running?
Storage option | Version 4.6 | Version 4.8 | Version 4.10 |
---|---|---|---|
OpenShift Data Foundation | ✓ | ✓ | ✓ |
OpenShift Data Foundation as a Service | ✓ | ||
IBM Spectrum Fusion | ✓ | ✓ | |
IBM Spectrum Scale Container Native | ✓ | ✓ | |
Portworx | ✓ | ✓ | ✓ |
NFS | ✓ | ✓ | ✓ |
Amazon Elastic Block Store (EBS) | ✓ | ✓ | ✓ |
Amazon Elastic File System (EFS) | ✓ | ✓ | ✓ |
IBM Cloud Block Storage | ✓ | ✓ | ✓ |
IBM Cloud File Storage | ✓ | ✓ | ✓ |
What storage options are supported on my hardware?
Storage option | x86-64 | Power® | s390x |
---|---|---|---|
OpenShift Data Foundation | ✓ | ||
OpenShift Data Foundation as a Service | ✓ | ||
IBM Spectrum Fusion | ✓ | ||
IBM Spectrum Scale Container Native | ✓ | ||
Portworx | ✓ | ||
NFS | ✓ | ✓ | ✓ |
Amazon Elastic Block Store (EBS) | ✓ | ||
Amazon Elastic File System (EFS) | ✓ | ||
IBM Cloud Block Storage | ✓ | ✓ | |
IBM Cloud File Storage | ✓ | ✓ |
License requirements
The following table lists whether you need a separate license to use each storage option. In some cases, your Guardium Insights purchase includes limited entitlements to the storage.
Storage option | Details |
---|---|
OpenShift Data Foundation | |
OpenShift Data Foundation as a Service | Contact IBM Support. |
IBM Spectrum Fusion | |
IBM Spectrum Scale Container Native (with IBM Spectrum Scale Container Storage Interface) | You can use IBM Spectrum Scale Container Native as part of IBM Spectrum Fusion. |
Portworx | A separate license is required. |
NFS | No license is required. |
Amazon Elastic Block Store (EBS) | A separate subscription is required. |
Amazon Elastic File System (EFS) | A separate subscription is required. |
IBM Cloud Block Storage | A separate subscription is required. |
IBM Cloud File Storage | A separate subscription is required. For details about the amount of storage you can use, see How many volumes can be ordered. |
Storage classes
The person who installs Guardium Insights and the services on the cluster must know which storage classes to use during installation. The following table lists the required types of storage. When applicable, the table also lists the recommended storage classes to use and points to additional guidance on how to create the storage classes.
Storage option | Details |
---|---|
OpenShift Data Foundation | The recommended storage classes are automatically created when you install OpenShift Data
Foundation. Guardium Insights uses the following storage classes:
|
OpenShift Data Foundation as a Service | The recommended storage classes are automatically created by OpenShift Data Foundation as a Service. Guardium Insights uses the following storage classes:
|
IBM Spectrum Fusion | . |
IBM Spectrum Scale Container Native (with IBM Spectrum Scale Container Storage Interface) | |
Portworx | The recommended storage classes are listed in Creating Portworx storage classes. |
NFS | |
Amazon Elastic Block Store (EBS) | Use either of the following RWO storage classes: |
Amazon Elastic File System (EFS) | |
IBM Cloud Block Storage | Use the following RWO storage class: |
IBM Cloud File Storage | Use either of the following RWX storage classes: |
Data replication for high availability
Storage option | Details |
---|---|
OpenShift Data Foundation | Supported By default, all services use multiple replicas for high availability. OpenShift Data Foundation maintains each replica in a distinct availability zone. |
OpenShift Data Foundation as a Service | All data on the persistent volumes is replicated across multiple availability zones by default. Cross-cluster asynchronous replication is not supported. |
IBM Spectrum Fusion | Supported. Replication is supported and can be enabled within the Spectrum Scale Storage Cluster in a variety of ways, see Data Mirroring and Replication in the IBM Spectrum Scale documentation. |
IBM Spectrum Scale Container Native (with IBM Spectrum Scale Container Storage Interface) | Supported. Replication is supported and can be enabled within the Spectrum Scale Storage Cluster in a variety of ways, see Data Mirroring and Replication in the IBM Spectrum Scale documentation. |
Portworx | |
NFS | Replication support depends on your NFS server. |
Amazon Elastic Block Store (EBS) | Supported When you create an EBS volume, it is automatically replicated within its Availability Zone to prevent data loss due to failure of any single hardware component. |
Amazon Elastic File System (EFS) | Supported You can use EFS replication to create a replica of your EFS file system in the AWS Region of your choice. When you enable replication on an EFS file system, Amazon EFS automatically and transparently replicates the data and metadata on the source file system to the target file system. For details, see Amazon EFS replication. |
IBM Cloud Block Storage | Supported You can create a snapshot schedule to automatically copy snapshots to a destination volume in a remote data center for Data replication. For details, see Replicating data in the IBM Cloud documentation. |
IBM Cloud File Storage | Supported, but not enabled by default. You can enable replication from the IBM Cloud console. For details, see Replicating data. |
Backup and restore
Storage option | Details |
---|---|
OpenShift Data Foundation | Container Storage Interface support for snapshots and clones. Tight integration with Velero CSI plugin for Red Hat OpenShift Container Platform backup and recovery. |
OpenShift Data Foundation as a Service | Contact IBM Support. |
IBM Spectrum Fusion | IBM Spectrum Protect
Plus is not supported for
application-consistent backup and restore. For storage level backup, see Back up and restore in the IBM Spectrum Fusion documentation. |
IBM Spectrum Scale Container Native (with IBM Spectrum Scale Container Storage Interface) | IBM Spectrum Protect
Plus is not supported for
application-consistent backup and restore. Use the IBM Spectrum Scale Container Storage Interface Volume snapshot as the primary backup and restore method and combine it with Container Backup Support provided by IBM Spectrum Protect Plus. Additionally, there are multiple methods you can use to backup the Spectrum Scale Storage Cluster. For details, see Data protection and disaster recovery in the IBM Spectrum Scale documentation. |
Portworx |
|
NFS | Limited support. |
Amazon Elastic Block Store (EBS) | |
Amazon Elastic File System (EFS) | |
IBM Cloud Block Storage | |
IBM Cloud File Storage | Supported, but not enabled by default. For details, see Backing up and restoring data. |
Encryption of data at rest
Storage option | Details |
---|---|
OpenShift Data Foundation | Supported. OpenShift Data Foundation uses Linux Unified Key System (LUKS) version 2 based encryption with a key size of 512 bits and the aes-xts-plain64 cipher. You must enable encryption for your whole cluster during cluster deployment to ensure encryption of data at rest. Encryption is disabled by default. Working with encrypted data incurs a small performance penalty.
|
OpenShift Data Foundation as a Service | |
IBM Spectrum Fusion | Supported For details, see Encryption in the IBM Spectrum Scale documentation. |
IBM Spectrum Scale Container Native (with IBM Spectrum Scale Container Storage Interface) | Supported For details, see Encryption in the IBM Spectrum Scale documentation. |
Portworx | Supported with Portworx Enterprise only.
Portworx uses the LUKS format of dm-crypt and AES-256 as the cipher with xts-plain64 as the cipher mode.
|
NFS | Check with your storage vendor on the steps to enable encryption of data at rest. |
Amazon Elastic Block Store (EBS) | |
Amazon Elastic File System (EFS) | |
IBM Cloud Block Storage | |
IBM Cloud File Storage | Supported IBM Cloud File Storage supports provider-managed encryption of data at rest. This feature is only available in select data centers. All storage that is ordered in these data centers is automatically provisioned with encryption for data at rest. All snapshots and replicas of encrypted file storage are also encrypted by default in these select data centers. |
Network and I/O requirements
Storage option | Details |
---|---|
OpenShift Data Foundation |
|
OpenShift Data Foundation as a Service |
|
IBM Spectrum Fusion |
|
IBM Spectrum Scale Container Native (with IBM Spectrum Scale Container Storage Interface) |
|
Portworx |
|
NFS |
|
Amazon Elastic Block Store (EBS) |
|
Amazon Elastic File System (EFS) |
|
IBM Cloud Block Storage |
|
IBM Cloud File Storage |
|
Resource requirements
This section describes the resource requirements for the various storage options.
For information about the minimum amount of storage that is required for your environment, see Storage requirements.
Storage Option | vCPU | Memory | Storage |
---|---|---|---|
OpenShift Data Foundation |
For details, see Resource requirements. |
For details, see Resource requirements. |
A minimum of three nodes. On each node, you must have at least one SSD or NVMe device. Each device should have at least 1TB of available storage. For details, see Storage device requirements. |
OpenShift Data Foundation as a Service | Contact IBM Support. | Contact IBM Support. | Contact IBM Support. |
IBM Spectrum Fusion | 8 vCPU on each worker node to deploy IBM Spectrum Scale Container
Native and IBM Spectrum
Scale Container Storage Interface Driver. See the IBM Spectrum Scale Container Native hardware requirements. |
16 GB of RAM on each worker node. For details, see the IBM Spectrum Scale Container Native requirements |
1 TB or more of available space |
IBM Spectrum Scale Container Native (with IBM Spectrum Scale Container Storage Interface) | 8 vCPU on each worker node to deploy IBM Spectrum Scale Container Native and IBM Spectrum Scale Container Storage Interface Driver. | 16 GB of RAM on each worker node. For details, see the IBM Spectrum Scale Container Native requirements |
1 TB or more of available space |
Portworx |
|
4 GB of RAM on each storage node | A minimum of three storage nodes. On each storage node, you must have:
|
NFS | 8 vCPU on the NFS server | 32 GB of RAM on the NFS server | 1 TB or more of available space |
Amazon Elastic Block Store (EBS) | |||
Amazon Elastic File System (EFS) | |||
IBM Cloud Block Storage | |||
IBM Cloud File Storage | Not applicable for managed services. | Not applicable for managed services | 500 GB or more Storage is not automatically expanded and is created in smaller chunks. Increasing the size of the volumes improves I/O performance for production environments. Contact IBM Software Support as indicated in the preceding row. If you are running the Prometheus Cluster Monitoring stack on IBM Cloud, you might notice that pods consume more local storage. You can reduce the retention periods of your logs or you can configure logs to be saved in persistent storage instead of local storage. For more information, see Configuring the monitoring stack. To troubleshoot issues, see Worker nodes show status of disk pressure. |
Additional documentation
Storage option | Documentation links |
---|---|
OpenShift Data Foundation |
|
OpenShift Data Foundation as a Service |
|
IBM Spectrum Fusion |
|
IBM Spectrum Scale Container Native (with IBM Spectrum Scale Container Storage Interface) |
|
Portworx |
|
NFS |
|
Amazon Elastic Block Store (EBS) |
|
Amazon Elastic File System (EFS) |
|
IBM Cloud Block Storage |
|
IBM Cloud File Storage |
|