IBM brings Digital Asset Haven on premises with OpenShift as the control plane
The beta moves custody and transaction services onto client-managed IBM Z or LinuxONE, while IBM’s availability reference configuration assigns local storage to OpenShift Data Foundation.
IBM has opened a beta of Digital Asset Haven that runs inside a customer’s data center, turning Red Hat OpenShift into the deployment substrate for a regulated digital-asset stack rather than requiring the public-cloud service. The initial target is narrower than “any OpenShift”: IBM says the beta runs on IBM Z and IBM LinuxONE and is intended for financial institutions, governments and other regulated organizations evaluating custody and transaction management under their own operational control.
What the architecture puts on premises
The customer-controlled deployment keeps both the Haven solution layer and its key-management layer inside the client environment. IBM lists wallet management, transaction signing, policy-based governance, Hyperledger Besu connectivity and transaction management among the platform’s functions. Hardware-backed key protection uses Crypto Express HSMs on LinuxONE, while partitioning separates production, test and development environments.
OpenShift’s role is the application platform and operational control plane: IBM describes Haven as running in client-managed Red Hat OpenShift environments on IBM Z or LinuxONE. That makes cluster lifecycle, access control, observability, resilience and application operations responsibilities for the customer and its platform team rather than properties hidden behind IBM’s SaaS boundary.
OpenShift Data Foundation has a more specific role. In the reference configuration behind IBM’s claimed 99.999999% availability figure, Red Hat OpenShift Data Foundation 4.14 or later manages local storage devices. The same footnote names Red Hat OpenShift 4.14 or later, z/VM Single System Image clustering, GDPS recovery components and IBM DS8000 storage with HyperSwap. IBM does not present that entire reference stack as the only supported beta topology, so the availability number should not be read as a blanket service-level commitment for every Haven deployment.
What the beta changes
Until now, IBM offered SaaS and hybrid deployment models. The on-premises beta gives organizations an early path to keep application services, keys, data and operations in their own data center without a public-cloud dependency. IBM says the architecture, APIs and workflows remain consistent with its other deployment models, which is meant to reduce application rewrites if an organization changes deployment models later.
The release also adds a beta ISO 20022 Messaging Adapter for Swift’s blockchain-based shared ledger. Haven supplies wallet infrastructure and blockchain connectivity; the adapter maps established ISO 20022 payment messages to on-chain transactions. IBM says participating institutions can use tokenized deposits around the clock while final settlement continues through existing financial-market infrastructure.
What platform teams should evaluate
This is an evaluation release, not a general-availability signal. Platform teams should separate the product beta from IBM’s reference availability claim, then test the operational boundaries that move in-house: OpenShift and ODF lifecycle ownership, HSM and key ceremonies, disaster recovery, storage failure domains, environment isolation and audit evidence. The architectural change is meaningful because sovereignty becomes deployable rather than contractual—but it also transfers day-two responsibility from IBM’s service boundary to the customer’s platform organization.
sources
comments · 0