QuestionQ48

Prepare the Environment for an NKP Deployment

A Platform Engineer is deploying NKP in a highly secure vSphere environment. The NKP cluster will be air-gapped and must be FIPS compliant. RHEL will be the OS platform for NKP cluster nodes.

What must the engineer do to correctly prepare an OS image and deploy it as a FIPS-compliant NKP cluster node?

Explanation

A RHEL node image must already operate in FIPS mode. For an air-gapped FIPS vSphere image, Konvoy Image Builder uses both offline-fips.yaml and fips.yaml overrides. Cluster deployment then specifies the official FIPS Kubernetes and etcd image repositories and version tags; no separate FIPS kubectl reference is required. Create FIPS 140 Images: Air-gapped Environment and FIPS 140-2 Compliance document these requirements.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!