Configuring FIPS mode

Configure Cloudera Streaming Analytics Operator for Kubernetes to run on FIPS-enabled OpenShift clusters.

Cloudera Streaming Analytics Operator for Kubernetes is not FIPS-certified by default. On FIPS-enabled OpenShift clusters installed on FIPS-enabled Red Hat nodes, you must supply FIPS-compatible cryptographic providers and rebuild or retag container images before the Flink Kubernetes Operator webhook and Cloudera SQL Stream Builder pods start successfully.

Crypto provider JARs, truststores, and image registries vary by environment; adjust the examples below for your deployment.

  • A FIPS-enabled OpenShift cluster with outbound access to your private container registry.
  • Customer-supplied FIPS crypto provider JARs (for example CryptoComply and Bouncy Castle JSSE) and a modified java.security file that registers them.
  • Cloudera Streaming Analytics Operator for Kubernetes Helm chart and license file for your target version.
  1. Install Cloudera Streaming Analytics Operator for Kubernetes with image repository overrides pointing at your registry namespace.
    At minimum, override images for the Flink Kubernetes Operator, Flink extended SQL runner, and Cloudera SQL Stream Builder SSE components in values.yaml.
  2. Build custom images for the Flink Kubernetes Operator webhook.
    1. Copy your FIPS provider JARs into a build context directory.
    2. Extract the stock java.security file from a running operator pod and add your providers at the top of the security.provider and fips.provider lists. Set fips.keystore.type to BCFKS.
    3. Build and push the image with docker build --platform linux/amd64 when building on a different architecture.
  3. Repeat the image customization for Flink extended and Cloudera SQL Stream Builder SSE images.
    Create BCFKS truststores for TLS endpoints your jobs connect to and mount them through Helm podVolumes / podVolumeMounts as needed.
  4. Update values.yaml with the custom image tags and roll out the release.
    Verify the Flink Kubernetes Operator webhook pod reaches Ready state and that Cloudera SQL Stream Builder SSE starts without JSSE or keystore errors.