---
name: deployable-reference-architectures-deploy-arch-ibm-slz-ocp
title: Landing zone for containerized applications with OpenShift - Standard (Financial Services edition)
description: The Landing zone for containerized applications with OpenShift is a deployable architecture solution that is based on the IBM Cloud for Financial Services reference architecture. It creates secure and compliant Red Hat OpenShift Container Platform workload clusters on a Virtual Private Cloud (VPC) network.
last-updated: 2024-09-26
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/deployable-reference-architectures?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Landing zone for containerized applications with OpenShift - Standard (Financial Services edition)
{: #ocp-ra}
{: toc-content-type="reference-architecture"}
{: toc-industry="Banking,FinancialSector"}
{: toc-use-case="Cybersecurity"}
{: toc-compliance="FedRAMP"}
{: toc-version="8.15.1"}

The Landing zone for containerized applications with OpenShift is a deployable architecture solution that is based on the IBM Cloud for Financial Services reference architecture. It creates secure and compliant Red Hat OpenShift Container Platform workload clusters on a Virtual Private Cloud (VPC) network.

## Architecture diagram
{: #ra-ocp-architecture-diagram}

![Architecture diagram of the OpenShift - Standard (Financial Services edition) on VPC deployable architecture](roks.drawio.svg "Architecture diagram of Landing zone for containerized applications with OpenShift - Standard (Financial Services edition) deployable architecture"){: caption="Single region architecture diagram for Landing zone for containerized applications with OpenShift" caption-side="bottom"}{: external download="roks.drawio.svg"}

## Design requirements
{: #ra-ocp-design-requirements}

![Design requirements for Secure infrastructure on VPC for regulated industries](heat-map-deploy-arch-slz-ocp.svg "Design requirements"){: caption="Scope of the design requirements" caption-side="bottom"}



## Components
{: #ra-ocp-components}

### VPC architecture decisions
{: #ra-ocp-components-arch}

| Requirement | Component | Reasons for choice | Alternative choice |
|-------------|-----------|--------------------|--------------------|
| Provide access management and tools for the workload that is deployed in the workload VPC | Management VPC service | Create a separate VPC service where SSH connectivity from outside is allowed | |
| Provide compute, storage, and network services to support hosted applications and operations that deliver services to the consumer | Workload VPC service | Create a separate VPC service as an isolated environment, without direct public internet connectivity and without direct SSH access | |
| * Demonstrate compliance with control requirements of the IBM Cloud Framework for Financial Services  \n * Set up network for all created services  \n * Isolate network for all created services  \n * Ensure all created services are interconnected | Secure landing zone components | Create a minimum set of required components for a secure landing zone | Create a modified set of required components for a secure landing zone in preset |
{: caption="Architecture decisions" caption-side="bottom"}

### Network security architecture decisions
{: #ra-ocp-components-arch-net-sec}

| Requirement | Component | Reasons for choice | Alternative choice |
|-------------|-----------|--------------------|--------------------|
| * Isolate management VPC and allow only a limited number of network connections  \n * All other connections from or to management VPC are forbidden | ACL and security group rules in management VPC | | More ports might be opened in preset or added manually after deployment |
| * Isolate workload VPC and allow only a limited number of network connections  \n * All other connections from or to workload VPC are forbidden | ACL and security group rules in workload VPC | Open following ports by default: 53 (DNS service)  \n All ports to other VPCs are open | More ports might be opened in preset or added manually after deployment |
| Enable floating IP on bastion host to run deployment | Floating IPs on bastion host in management VPC|Use floating IP on bastion host from IBM Schematics to complete deployment | |
| Load VPN configuration to simplify VPN setup | VPNs | VPN configuration is the responsibility of the customer | |
| Collect and store Internet Protocol (IP) traffic information with Activity Tracker and Flow Logs | Activity Tracker | | |
| Securely connect to multiple networks with a site-to-site virtual private network | | | |
{: caption="Network security architecture decisions" caption-side="bottom"}



## Next steps
{: #ra-ocp-next-steps}

If you plan to use Red Hat OpenShift on IBM Cloud, explore a more detailed view of the [VPC reference architecture with Red Hat OpenShift on IBM Cloud](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-vpc-architecture-detailed-openshift&format=markdown)