Cloud Platform as a Service

Cloud Platform as a Service

Join us to learn more from a community of collaborative experts and IBM Cloud product users to share advice and best practices with peers and stay up to date regarding product enhancements, regional user group meetings, webinars, how-to blogs, and other helpful materials.

 View Only

IBM Cloud Containers - Dec 2023 "Spain ENS High Certification"

By John Wen posted Wed January 10, 2024 03:08 PM

  

Announcing new features that have been shipped in the December 2023 along with the value they provide to new, existing, and prospective users. Create your cluster now!

OpenShift 4.14 is now available in RedHat OpenShift on IBM Cloud

  • With our 13th release of OpenShift, users can take advantage of currency and security changes such as Red Hat OpenShift on IBM Cloud now supports oc login --web so that user logs into their OIDC identity provider securely increasing cluster security.

  • In 4.14 upgrade requires OpenShift cluster version currency and Upgrade requires resolution to OpenShift cluster version upgradeable conditions which further enhances cluster upgrade experience by ensuring clusters are healthy and if not, we provide help guide them on the problems to fix before the upgrade.

VPC clusters at IKS 1.28+ and ROKS 4.14+ now pull container images from the IBM Container Registry through a Virtual Private Endpoint (VPE) Gateway.

  • This VPE Gateway exists in the VPC and uses IP addresses in the same VPC subnets as the cluster workers, making it easier to filter this cluster worker to container registry traffic using custom security group rules.

  • This is all configured automatically in the VPC when the first cluster in that VPC is created/upgraded to IKS 1.28 or ROKS 4.14, and the VPE Gateway is used by all clusters in that VPC

Master to communication is now performed using Konnectivity

  • Konnectivity, a community-based encrypted proxy specific for Kubernetes, will replace OpenVPN which improves performance and stability for master to cluster communication such as kubectl logs , kubectl exec, and webhooks.

Spain ENS High Certification - Red Hat OpenShift on IBM Cloud, IBM Kubernetes Service, IBM Container Registry

  • The Esquema Nacional de Seguridad (ENS) (National Security Framework) aims to establish a security policy for the use of electronic media in Spain.

  • Adherence to ENS High enables a high level of cybersecurity measures—safeguarding against potential threats and vulnerabilities showcasing IBM’s commitment to protecting sensitive data.

Worker ordering during a scale down

  • There is now a documented selection process that IKS and ROKS automation works through to select which workers are removed from a cluster during a scaledown operation.

  • The addition of the selection process opens up an opportunity for our customers to scale their worker pools with confidence and ease the replacement of workers within their workerpool when updates are required.

0 comments
18 views

Permalink