November 14, 2019 By Chris Rosen
Sowmya Nataraj
3 min read

Announcing the integration of Red Hat OpenShift on IBM Cloud and IBM Cloud Kubernetes Service with IBM Cloud Hyper Protect Crypto Services.

Moving confidential data and workloads to the cloud brings up challenges with ensuring the right security controls are in place to protect the data. Customers want to ensure that their data and IP are safe from both internal and external threats. IBM recently announced industry-leading security capabilities to enable enterprise customers who are looking to store highly sensitive data in the public cloud.

The industry’s highest level of encryption key protection is now available for IBM Cloud Kubernetes Service and Red Hat OpenShift on IBM Cloud through integration with IBM Cloud Hyper Protect Crypto Services.

What is IBM Cloud Hyper Protect Crypto Services?

IBM Cloud Hyper Protect Crypto Services is a single-tenant Key Management Service and a Cloud Hardware Security Module (HSM) service. Key vaulting is provided by dedicated, customer-controlled cloud HSMs that are built on FIPS 140-2 Level 4-certified (tamper-proof) hardware, the highest offered by any cloud provider in the industry. The service offers Keep Your Own Key (KYOK) capabilities, which allow customers to have exclusive key control— only authorized users have access (no privileged users, including IBM Cloud admins, have access) to encryption keys.

What is Red Hat OpenShift on IBM Cloud?

Red Hat OpenShift on IBM Cloud is a managed service that simplifies deployment and configuration of the OpenShift Container Platform. As a managed service, IBM will automate initial provisioning as well as ongoing maintenance, including operating system patches, vulnerability remediation, and any updates in the OpenShift stack. 

What is the IBM Cloud Kubernetes Service?

IBM Cloud Kubernetes Service is a managed container service offering that leverages Kubernetes as the container orchestration solution. It delivers powerful management tools, an intuitive user experience, and built-in security and isolation to enable rapid delivery of applications, all while leveraging Cloud Services and cognitive capabilities from Watson. As a certified CNCF K8s provider, IBM Cloud Kubernetes Service provides native Kubernetes capabilities like intelligent scheduling, self-healing, horizontal scaling, service discovery and load balancing, automated rollouts and rollbacks, and secret and configuration management.

Protecting sensitive data in applications

When it comes to cloud native applications built with Kubernetes, data protection should cover both Kubernetes secrets and the persistent datastores used by the apps. IBM Cloud Kubernetes Service already provides support for Bring Your Own Key (BYOK) through integration with IBM Key Protect. Key Protect is a multi-tenant service with key vaulting provided by IBM-controlled, FIPS 140-2 Level 3 certified Hardware Security Modules (HSM).

Exclusive key control with KYOK

Customers looking to safeguard highly sensitive data want to use their own keys for encryption and also require complete control of their encryption keys. For these customers, Hyper Protect Crypto Services provides exclusive control over the entire key hierarchy, including the master key of the HSM that protects the secrets. The Level-4 certification assures that the HSM is tamper-proof—it can sense any attempt to compromise the HSM via physical, chemical, or environmental changes and immediately responds by auto-erasing the keys stored, which then invalidates the data that the keys protect.

  • Kubernetes secrets: A secret is an object that stores sensitive data like a password, a token, or a key. There are built-in secrets that are created automatically by Kubernetes, such as the secret containing credentials for access the API endpoint. There are also user-created secrets, such as storing access information to leverage other IBM Cloud services, including Watson and IBM Cloud Container Registry. By default, the Kubernetes master (API server) stores secrets as base64 encoded plain text in etcd. In order to enable customer-managed encryption control for the secrets, IBM Kubernetes Service now provides support for Keep Your Own Key (KYOK) through integration with Hyper Protect Crypto Services.
  • Persistent datastores used by the app: IBM Cloud Kubernetes Service allows customers to store data on persistent storage. Supported storage types include VPC Block Storage and Cloud Object Storage, both of which integrate with Hyper Protect Crypto Services to provide customers with KYOK capability.

The KYOK integration is also available for Red Hat OpenShift on IBM Cloud for protection of Kubernetes secrets.

Learn more

For more information, see “Protecting sensitive information in your cluster.”

For general questions, engage our team via Slack by registering here and join the discussion in the #general channel on our public IBM Cloud Kubernetes Service Slack.

More from Cloud

New 4th Gen Intel Xeon profiles and dynamic network bandwidth shake up the IBM Cloud Bare Metal Servers for VPC portfolio

3 min read - We’re pleased to announce that 4th Gen Intel® Xeon® processors on IBM Cloud Bare Metal Servers for VPC are available on IBM Cloud. Our customers can now provision Intel’s newest microarchitecture inside their own virtual private cloud and gain access to a host of performance enhancements, including more core-to-memory ratios (21 new server profiles/) and dynamic network bandwidth exclusive to IBM Cloud VPC. For anyone keeping track, that’s 3x as many provisioning options than our current 2nd Gen Intel Xeon…

IBM and AWS: Driving the next-gen SAP transformation  

5 min read - SAP is the epicenter of business operations for companies around the world. In fact, 77% of the world’s transactional revenue touches an SAP system, and 92% of the Forbes Global 2000 companies use SAP, according to Frost & Sullivan.   Global challenges related to profitability, supply chains and sustainability are creating economic uncertainty for many companies. Modernizing SAP systems and embracing cloud environments like AWS can provide these companies with a real-time view of their business operations, fueling growth and increasing…

Experience unmatched data resilience with IBM Storage Defender and IBM Storage FlashSystem

3 min read - IBM Storage Defender is a purpose-built end-to-end data resilience solution designed to help businesses rapidly restart essential operations in the event of a cyberattack or other unforeseen events. It simplifies and orchestrates business recovery processes by providing a comprehensive view of data resilience and recoverability across primary and  auxiliary storage in a single interface. IBM Storage Defender deploys AI-powered sensors to quickly detect threats and anomalies. Signals from all available sensors are aggregated by IBM Storage Defender, whether they come…

IBM Newsletters

Get our newsletters and topic updates that deliver the latest thought leadership and insights on emerging trends.
Subscribe now More newsletters