[go: up one dir, main page]

Skip to contentRed Hat

Navigation

AI
  • Our approach

    • News and insights
    • Technical blog
    • Research
    • Live AI events
    • Explore AI at Red Hat
  • Our portfolio

    • Red Hat AI
    • Red Hat Enterprise Linux AI
    • Red Hat OpenShift AI
    • Red Hat AI Inference Server
  • Engage & learn

    • AI learning hub
    • AI partners
    • Services for AI
Hybrid cloud
  • Platform solutions

    • Artificial intelligence

      Build, deploy, and monitor AI models and apps.

    • Linux standardization

      Get consistency across operating environments.

    • Application development

      Simplify the way you build, deploy, and manage apps.

    • Automation

      Scale automation and unite tech, teams, and environments.

    • Explore solutions
  • Use cases

    • Virtualization

      Modernize operations for virtualized and containerized workloads.

    • Digital sovereignty

      Control and protect critical infrastructure.

    • Security

      Code, build, deploy, and monitor security-focused software.

    • Edge computing

      Deploy workloads closer to the source with edge technology.

  • Solutions by industry

    • Automotive
    • Financial services
    • Healthcare
    • Industrial sector
    • Media and entertainment
    • Public sector
    • Telecommunications

Discover cloud technologies

Learn how to use our cloud products and solutions at your own pace in the Red Hat® Hybrid Cloud Console.

Products
  • Platforms

    • Red Hat AI

      Develop and deploy AI solutions across the hybrid cloud.

    • Red Hat Enterprise Linux

      Support hybrid cloud innovation on a flexible operating system.

    • Red Hat OpenShift

      Build, modernize, and deploy apps at scale.

    • Red Hat Ansible Automation Platform

      Implement enterprise-wide automation.

  • Featured

    • Red Hat OpenShift Virtualization Engine
    • Red Hat OpenShift Service on AWS
    • Microsoft Azure Red Hat OpenShift
    • See all products
  • Try & buy

    • Start a trial
    • Buy online
    • Integrate with major cloud providers
  • Services & support

    • Consulting
    • Product support
    • Services for AI
    • Technical Account Management
    • Explore services
Training
  • Training & certification

    • Courses and exams
    • Certifications
    • Red Hat Academy
    • Learning community
    • Learning subscription
    • Explore training
  • Featured

    • Red Hat Certified System Administrator exam
    • Red Hat System Administration I
    • Red Hat Learning Subscription trial (No cost)
    • Red Hat Certified Engineer exam
    • Red Hat Certified OpenShift Administrator exam
  • Services

    • Consulting
    • Partner training
    • Product support
    • Services for AI
    • Technical Account Management
Learn
  • Build your skills

    • Documentation
    • Hands-on labs
    • Hybrid cloud learning hub
    • Interactive learning experiences
    • Training and certification
  • More ways to learn

    • Blog
    • Events and webinars
    • Podcasts and video series
    • Red Hat TV
    • Resource library

For developers

Discover resources and tools to help you build, deliver, and manage cloud-native applications and services.

Partners
  • For customers

    • Our partners
    • Red Hat Ecosystem Catalog
    • Find a partner
  • For partners

    • Partner Connect
    • Become a partner
    • Training
    • Support
    • Access the partner portal

Build solutions powered by trusted partners

Find solutions from our collaborative community of experts and technologies in the Red Hat® Ecosystem Catalog.

Search

I'd like to:

  • Start a trial
  • Manage subscriptions
  • See Red Hat jobs
  • Explore tech topics
  • Contact sales
  • Contact customer service

Help me find:

  • Documentation
  • Developer resources
  • Skills assessments
  • Architecture center
  • Security updates
  • Support cases

I want to learn more about:

  • AI
  • Application modernization
  • Automation
  • Cloud-native applications
  • Linux
  • Virtualization
ConsoleDocsSupportNew For you

Recommended

We'll recommend resources you may like as you browse. Try these suggestions for now.

  • Product trial center
  • Courses and exams
  • All products
  • Tech topics
  • Resource library
Log in

Sign in or create an account to get more from Red Hat

  • World-class support
  • Training resources
  • Product trials
  • Console access

A subscription may be required for some services.

Log in or register
Contact us
  • Home
  • Resources
  • Microsoft Azure Red Hat OpenShift security FAQ

Microsoft Azure Red Hat OpenShift security FAQ

April 6, 2023•
Resource type: FAQ
Download PDF

SRE access

How do site reliability engineers (SREs) access my Microsoft Azure Red Hat® OpenShift® cluster? Does it go through the public internet?

Answer: SREs access the cluster through Azure Private Link, which maps private points to Azure resources.

See the cluster configuration requirements section.

What permissions do I need to run an Azure Red Hat OpenShift cluster?

Answer: To deploy and run an Azure Red Hat OpenShift cluster, you will need to create a service principal. You can create a service principal by using the Azure command-line interface (CLI) or PowerShell. In this case, you will need sufficient permissions to create the application on Azure Active Directory—either a member user of the tenant or a guest user that has been assigned the application administrator role.

If a service principal already exists and is provided for the deployment of the Azure Red Hat OpenShift cluster, you do not need the aforementioned permissions on Azure Active Directory.

In both cases, the service principal needs the roles contributor and user access administrator.

What is the identity and access management (IAM) policy for either of the above?

Answer: The service principal needs to have the roles contributor and user access administrator.

See link.

What level of access do SREs have to my Azure Red Hat OpenShift cluster? Can they access my applications and data?

Answer: No, the SREs can only access the Azure Red Hat OpenShift at platform level (control plane nodes). They use the connection through an Azure Private Link that allows communication to an internal load balancer behind the control plane nodes. The worker nodes—where applications run—are behind a different load balancer, which SREs do not have access to.

If an SRE needs access to my cluster, what is the process for gaining access and how is auditing handled?

Answer: Audit logs are generated and kept and customers can request them.

SRE personnel objections

Where are SREs located?

Answer: There is no list of locations for SREs.

Our company has a policy on not using services from a particular country, can we exclude this country from having SREs work on our cluster?

Answer: This is not possible as of now.

Customer process and tooling

InfoSec requires us to install a traditional security tool on all servers. Can I install these on the Azure Red Hat OpenShift hosts?

Answer: Azure Red Hat OpenShift hosts run CoreOS, which is an OS with the bare minimum and is not intended to have anything that does not come out of the box installed on it.

Can we get access to the SRE logging system and forward to our centralized logging solution?

Answer: For cluster operations and audit, the customer cluster administrators can deploy an optional logging stack to aggregate all logs from their Azure Red Hat OpenShift cluster. For example, administrators can aggregate node system audit logs and infrastructure logs. However, these logs consume other cluster resources.

The virtual machine (VM) logs where the nodes run are not exposed to customers.

What steps are taken to harden the Azure Red Hat OpenShift cluster?

Answer: Using Azure Front Door, Azure Private Link, the internal load balancers, and Azure Firewall—as shown in the portfolio architecture—ensures the protection of the Azure Red Hat OpenShift cluster.

Tags:Cloud services, Containers, Security, Managed cloud

Red Hat logoLinkedInYouTubeFacebookX

Platforms

  • Red Hat AI
  • Red Hat Enterprise Linux
  • Red Hat OpenShift
  • Red Hat Ansible Automation Platform
  • See all products

Tools

  • Training and certification
  • My account
  • Customer support
  • Developer resources
  • Find a partner
  • Red Hat Ecosystem Catalog
  • Documentation

Try, buy, & sell

  • Product trial center
  • Red Hat Store
  • Buy online (Japan)
  • Console

Communicate

  • Contact sales
  • Contact customer service
  • Contact training
  • Social

About Red Hat

Red Hat is an open hybrid cloud technology leader, delivering a consistent, comprehensive foundation for transformative IT and artificial intelligence (AI) applications in the enterprise. As a trusted adviser to the Fortune 500, Red Hat offers cloud, developer, Linux, automation, and application platform technologies, as well as award-winning services.

  • Our company
  • How we work
  • Customer success stories
  • Analyst relations
  • Newsroom
  • Open source commitments
  • Our social impact
  • Jobs

Change page language

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility