November 14, 2019 By Chris Rosen
Sowmya Nataraj
3 min read

Announcing the integration of Red Hat OpenShift on IBM Cloud and IBM Cloud Kubernetes Service with IBM Cloud Hyper Protect Crypto Services.

Moving confidential data and workloads to the cloud brings up challenges with ensuring the right security controls are in place to protect the data. Customers want to ensure that their data and IP are safe from both internal and external threats. IBM recently announced industry-leading security capabilities to enable enterprise customers who are looking to store highly sensitive data in the public cloud.

The industry’s highest level of encryption key protection is now available for IBM Cloud Kubernetes Service and Red Hat OpenShift on IBM Cloud through integration with IBM Cloud Hyper Protect Crypto Services.

What is IBM Cloud Hyper Protect Crypto Services?

IBM Cloud Hyper Protect Crypto Services is a single-tenant Key Management Service and a Cloud Hardware Security Module (HSM) service. Key vaulting is provided by dedicated, customer-controlled cloud HSMs that are built on FIPS 140-2 Level 4-certified (tamper-proof) hardware, the highest offered by any cloud provider in the industry. The service offers Keep Your Own Key (KYOK) capabilities, which allow customers to have exclusive key control— only authorized users have access (no privileged users, including IBM Cloud admins, have access) to encryption keys.

What is Red Hat OpenShift on IBM Cloud?

Red Hat OpenShift on IBM Cloud is a managed service that simplifies deployment and configuration of the OpenShift Container Platform. As a managed service, IBM will automate initial provisioning as well as ongoing maintenance, including operating system patches, vulnerability remediation, and any updates in the OpenShift stack. 

What is the IBM Cloud Kubernetes Service?

IBM Cloud Kubernetes Service is a managed container service offering that leverages Kubernetes as the container orchestration solution. It delivers powerful management tools, an intuitive user experience, and built-in security and isolation to enable rapid delivery of applications, all while leveraging Cloud Services and cognitive capabilities from Watson. As a certified CNCF K8s provider, IBM Cloud Kubernetes Service provides native Kubernetes capabilities like intelligent scheduling, self-healing, horizontal scaling, service discovery and load balancing, automated rollouts and rollbacks, and secret and configuration management.

Protecting sensitive data in applications

When it comes to cloud native applications built with Kubernetes, data protection should cover both Kubernetes secrets and the persistent datastores used by the apps. IBM Cloud Kubernetes Service already provides support for Bring Your Own Key (BYOK) through integration with IBM Key Protect. Key Protect is a multi-tenant service with key vaulting provided by IBM-controlled, FIPS 140-2 Level 3 certified Hardware Security Modules (HSM).

Exclusive key control with KYOK

Customers looking to safeguard highly sensitive data want to use their own keys for encryption and also require complete control of their encryption keys. For these customers, Hyper Protect Crypto Services provides exclusive control over the entire key hierarchy, including the master key of the HSM that protects the secrets. The Level-4 certification assures that the HSM is tamper-proof—it can sense any attempt to compromise the HSM via physical, chemical, or environmental changes and immediately responds by auto-erasing the keys stored, which then invalidates the data that the keys protect.

  • Kubernetes secrets: A secret is an object that stores sensitive data like a password, a token, or a key. There are built-in secrets that are created automatically by Kubernetes, such as the secret containing credentials for access the API endpoint. There are also user-created secrets, such as storing access information to leverage other IBM Cloud services, including Watson and IBM Cloud Container Registry. By default, the Kubernetes master (API server) stores secrets as base64 encoded plain text in etcd. In order to enable customer-managed encryption control for the secrets, IBM Kubernetes Service now provides support for Keep Your Own Key (KYOK) through integration with Hyper Protect Crypto Services.
  • Persistent datastores used by the app: IBM Cloud Kubernetes Service allows customers to store data on persistent storage. Supported storage types include VPC Block Storage and Cloud Object Storage, both of which integrate with Hyper Protect Crypto Services to provide customers with KYOK capability.

The KYOK integration is also available for Red Hat OpenShift on IBM Cloud for protection of Kubernetes secrets.

Learn more

For more information, see “Protecting sensitive information in your cluster.”

For general questions, engage our team via Slack by registering here and join the discussion in the #general channel on our public IBM Cloud Kubernetes Service Slack.

More from Cloud

Attention new clients: exciting financial incentives for VMware Cloud Foundation on IBM Cloud

4 min read - New client specials: Get up to 50% off when you commit to a 1- or 3-year term contract on new VCF-as-a-Service offerings, plus an additional value of up to USD 200K in credits through 30 June 2025 when you migrate your VMware workloads to IBM Cloud®.1 Low starting prices: On-demand VCF-as-a-Service deployments begin under USD 200 per month.2 The IBM Cloud benefit: See the potential for a 201%3 return on investment (ROI) over 3 years with reduced downtime, cost and…

24 IBM offerings winning TrustRadius 2024 Top Rated Awards

2 min read - TrustRadius is a buyer intelligence platform for business technology. Comprehensive product information, in-depth customer insights and peer conversations enable buyers to make confident decisions. “Earning a Top Rated Award means the vendor has excellent customer satisfaction and proven credibility. It’s based entirely on reviews and customer sentiment,” said Becky Susko, TrustRadius, Marketing Program Manager of Awards. Top Rated Awards have to be earned: Gain 10+ new reviews in the past 12 months Earn a trScore of 7.5 or higher from…

IBM Tech Now: April 8, 2024

< 1 min read - ​Welcome IBM Tech Now, our video web series featuring the latest and greatest news and announcements in the world of technology. Make sure you subscribe to our YouTube channel to be notified every time a new IBM Tech Now video is published. IBM Tech Now: Episode 96 On this episode, we're covering the following topics: IBM Cloud Logs A collaboration with IBM watsonx.ai and Anaconda IBM offerings in the G2 Spring Reports Stay plugged in You can check out the…

IBM Newsletters

Get our newsletters and topic updates that deliver the latest thought leadership and insights on emerging trends.
Subscribe now More newsletters