Configure Cloudera Streaming Analytics Operator for Kubernetes to run on FIPS-enabled OpenShift
clusters.
Cloudera Streaming Analytics Operator for Kubernetes is not FIPS-certified by default. On FIPS-enabled
OpenShift clusters installed on FIPS-enabled Red Hat nodes, you must supply FIPS-compatible
cryptographic providers and rebuild or retag container images before the Flink Kubernetes
Operator webhook and Cloudera SQL Stream Builder pods start successfully.
Crypto provider JARs, truststores, and image registries vary by environment; adjust the
examples below for your deployment.
A FIPS-enabled OpenShift cluster with outbound access to your private container
registry.
Customer-supplied FIPS crypto provider JARs (for example CryptoComply and Bouncy Castle
JSSE) and a modified java.security file that registers them.
Cloudera Streaming Analytics Operator for Kubernetes Helm chart and license file for your target
version.
Install Cloudera Streaming Analytics Operator for Kubernetes with image repository overrides
pointing at your registry namespace.
At minimum, override images for the Flink Kubernetes Operator, Flink extended SQL
runner, and Cloudera SQL Stream Builder SSE components in
values.yaml.
Build custom images for the Flink Kubernetes Operator webhook.
Copy your FIPS provider JARs into a build context directory.
Extract the stock java.security file from a running operator pod
and add your providers at the top of the security.provider and
fips.provider lists. Set fips.keystore.type to
BCFKS.
Build and push the image with docker build --platform
linux/amd64 when building on a different architecture.
Repeat the image customization for Flink extended and Cloudera SQL Stream Builder
SSE images.
Create BCFKS truststores for TLS endpoints your jobs connect to and mount them through
Helm podVolumes / podVolumeMounts as needed.
Update values.yaml with the custom image tags and roll out the
release.
Verify the Flink Kubernetes Operator webhook pod reaches Ready state and that Cloudera SQL Stream Builder SSE starts without JSSE or keystore errors.