Azure Red Hat OpenShift Government reaches the DoD IL5 boundary
The certification opens the managed OpenShift service to higher-sensitivity CUI and unclassified national-security workloads in Microsoft Azure Government.
Microsoft Azure Red Hat OpenShift for Azure Government has attained US Department of Defense Impact Level 5 certification, extending the jointly operated managed OpenShift service to a class of sensitive government workloads that IL4 did not cover.
Red Hat announced the certification on September 24. The company says agencies can now use the service to build, deploy and run containerized applications subject to IL5 controls, including higher-sensitivity Controlled Unclassified Information, unclassified National Security Systems and mission-critical information.
What changed
The product is not a new OpenShift distribution. The change is the compliance boundary around the existing Azure Red Hat OpenShift service in Microsoft Azure Government.
Azure Red Hat OpenShift for Azure Government launched in 2023 and reached IL4 certification in July 2024. Red Hat says the service also holds FedRAMP High authorization and certifications or compliance coverage associated with ITAR, DFARS, IRS Publication 1075 and CJIS requirements.
IL5 adds a higher Department of Defense impact level. Red Hat says the assessment covered security controls around continuous patching, scanning and vulnerability remediation. Those controls sit alongside the service’s existing model: Red Hat and Microsoft co-develop and jointly operate the platform rather than handing agencies an OpenShift environment they must fully manage themselves.
Who should care
The immediate audience is US public-sector platform teams that need a managed Kubernetes and application platform for workloads above the IL4 boundary. The certification can remove a procurement and authorization blocker for programs handling higher-sensitivity CUI or unclassified national-security workloads.
It also matters to application teams whose deployment target is Azure Government. They can use the familiar OpenShift application model without taking on every layer of control-plane operations, while their security and compliance teams evaluate the service inside an IL5-authorized scope.
The announcement does not mean every application placed on the service becomes compliant automatically. Agencies still have to map their own systems, configurations, data handling and operational controls to the applicable authorization package. The useful change is that the underlying managed OpenShift service is now eligible for that work at IL5.
What to do next
Government platform owners should confirm the exact Azure Government regions, service features and connected services covered by the authorization before planning a migration. They should also compare the shared-responsibility model with controls currently implemented on self-managed OpenShift.
For teams already running Azure Red Hat OpenShift Government under IL4, the practical next step is a gap review: identify workloads previously excluded by impact level, then validate whether the service’s IL5 scope and regional availability match their authorization requirements.
sources
comments · 0