What's new in version 1.2.1
New features and enhancements in version 1.2.1, including a product rename, Bare Metal support, encrypted persistent block storage, an updated image, and certificate expiry improvements.
- Product renamed from IBM Hyper Protect Confidential Container for Red Hat OpenShift Container Platform to IBM Confidential Computing Containers for Red Hat OpenShift Container Platform
- The product name is changed from IBM Hyper Protect Confidential Container for Red Hat OpenShift Container Platform to IBM Confidential Computing Containers for Red Hat OpenShift Container Platform. All features and functionalities continue to work as before. For more information, see Revised technical information.
- Enablement of Bare Metal
-
With this release, IBM Confidential Computing Containers for Red Hat OpenShift Container Platform introduces support for Bare Metal environments, delivering significant enhancements in performance, observability, and security. The Bare Metal deployments enables workloads to run directly on LPAR which acts as compute nodes, improving performance, simplifying architecture, and enhancing operational efficiency:
- Improved resource visibility
- The peer pod model hid the resource consumption by individual peer pods, making monitoring and scaling difficult. The new approach offers clear visibility into resource usage, making it easier for administrators to track performance and manage the cluster effectively.
- Enhanced security and performance efficiency
- The updated model allows secure workloads to run directly within the Logical Partition (LPAR). This change eliminates the need for double nesting, simplifying the system and reducing performance overhead for greater overall efficiency.
- Better observability and resource management:
- The new model provides advanced monitoring tools for managing resources across the environment. This improved observability enables IT teams to gain insights into system performance and optimize resource utilization, ensuring all components operate efficiently.
- Encrypted persistent block storage support
-
The Bare Metal IBM Confidential Computing Containers for Red Hat OpenShift Container Platform deployment now supports encrypted persistent block storage, allowing you to attach encrypted block volumes to your confidential containers. This feature ensures that data stored on persistent volumes remains encrypted at rest, maintaining the confidentiality and integrity of your sensitive workloads.
- Updated image
-
You can get the latest IBM Confidential Computing Containers for Red Hat OpenShift Container Platform image from Passport Advantage. For more information, see Downloading the IBM Confidential Computing Containers for Red Hat OpenShift Container Platform image and uploading it to the remote registry.
- Update to certificate expiry dates
- The certificate expiry dates has been updated. For more information, see Certificate expiry dates.
- Encryption and Attestation certificate expiry warning logs
- CCCO now logs warning messages to the configured logging service to alert users about upcoming and expired encryption and attestation certificates. For more information, see Encryption and Attestation certificate expiry warning logs.