API and API Product FIPS compliance
The API and API Product Kubernetes resources can be implemented in a FIPS-compliant manner, with the following requirements and exceptions.
Requirements
The API Manager must be FIPS compliant. This is the case for API Managers on the same OpenShift cluster or on another OpenShift cluster. For more information, see API Connect cluster FIPS compliance.
Ensure that you use FIPs compliant connection secrets as described in Configuring FIPS support on OpenShift.
Limitations
For a FIPS compliant deployment, consider the following:
When using API and API Product Kubernetes resources, a user can potentially connect to an external API Manager that is not FIPS compliant. The user is responsible for ensuring that they are connecting to a FIPS-compliant API Manager.