After much anticipation, Red Hat OpenShift Service on AWS (ROSA) with hosted control planes in AWS GovCloud is now authorized against the FedRAMP High baseline controls in accordance with the Rev 5 authorization path. This means that customers are now able to use the hosted control plane architecture with ROSA in the AWS Government Community Cloud (GovCloud). 

The hosted control plane architecture, based on the HyperShift project, streamlines ROSA in AWS GovCloud classic architecture by providing a more effective and efficient use of customer resources, which can lead to improved security posture, operational efficiency, and cost savings. 

As part of the FedRAMP Authorization Act of 2022, the Federal Risk and Authorization Management Program (FedRAMP) was codified into law after 11 years of operation as a program. With this change, the FedRAMP Program Management Office (PMO) was empowered to find ways to accelerate procurement of commercial cloud service products to the federal government. While the experimental FedRAMP 20-X path to authorization comes into development, the traditional agency authorization path is now known as a “Rev 5 Authorization” in alignment with NIST 800-53 rev. 5, upon which it’s based. 

Since becoming authorized and listed on the FedRAMP Marketplace in 2024, Red Hat has continued to evolve to meet the demands of U.S. government agencies and their partners. ROSA with hosted control planes is the latest iteration of that journey. 

Some of the key customer benefits include:

  • Improved security posture: Since the control plane is hosted in a Red Hat-owned AWS service account, site reliability engineers (SREs) at Red Hat do not require broad permissions to manage those resources within the customer's AWS environment.
  • Enhanced operational reliability: Red Hat manages the underlying hosted control plane infrastructure, freeing you from operational overhead and reducing the chance of accidental misconfiguration or deletion of resources.
  • Reduced costs: ROSA with hosted control planes reduces the overall infrastructure footprint compared to ROSA on AWS classic deployments by eliminating the need for provisioning the infrastructure, leading to lower operational costs.
  • Faster cluster lifecycle management: You can quickly spin up or tear down clusters to optimize resources and reduce costs by only paying for what you use.

The second point is especially critical for anyone operating under FedRAMP requirements. With Red Hat managing the infrastructure entirely, software providers are able to reduce the scope of their own FedRAMP assessment even further than before. By taking advantage of the FedRAMP-Authorized ROSA with hosted control planes in AWS GovCloud, customers can see their own assessment scope reduced by up to approximately 70% of the FedRAMP High baseline controls. 

Not only will the initial assessment be faster, but because Red Hat is managing the infrastructure the monthly continuous monitoring requirements are also reduced in scope. This helps alleviate the Day 2 operational burden that those offering FedRAMP services often underestimate. This means customers can focus on delivering high quality products faster and more efficiently to their customers.

Additional resources 

제품 체험판

Red Hat OpenShift Service on AWS 시작하기

Red Hat OpenShift Service on AWS를 시작하세요. AWS에서 기본적으로 실행되는 관리형 OpenShift 서비스를 제공하는 턴키 애플리케이션 플랫폼에 대한 액세스 권한이 제공됩니다.

저자 소개

Josh Blaher is the FedRAMP Product Manager at Red Hat. He has spent more than a decade in the Federal IT space, supporting and leading a variety of transformative cloud solutions. He is an award-winning wildlife photographer who resides in Washington, DC with his partner and their cat.

UI_Icon-Red_Hat-Close-A-Black-RGB

채널별 검색

automation icon

오토메이션

기술, 팀, 인프라를 위한 IT 자동화 최신 동향

AI icon

인공지능

고객이 어디서나 AI 워크로드를 실행할 수 있도록 지원하는 플랫폼 업데이트

open hybrid cloud icon

오픈 하이브리드 클라우드

하이브리드 클라우드로 더욱 유연한 미래를 구축하는 방법을 알아보세요

security icon

보안

환경과 기술 전반에 걸쳐 리스크를 감소하는 방법에 대한 최신 정보

edge icon

엣지 컴퓨팅

엣지에서의 운영을 단순화하는 플랫폼 업데이트

Infrastructure icon

인프라

세계적으로 인정받은 기업용 Linux 플랫폼에 대한 최신 정보

application development icon

애플리케이션

복잡한 애플리케이션에 대한 솔루션 더 보기

Virtualization icon

가상화

온프레미스와 클라우드 환경에서 워크로드를 유연하게 운영하기 위한 엔터프라이즈 가상화의 미래