IBM & Red Hat on AWS
Confluent Platform on Red Hat OpenShift Service on AWS (ROSA)
Organizations managing growing volumes of real-time data need a reliable, scalable streaming backbone to maintain operational efficiency and accelerate digital transformation. Confluent Platform on Red Hat OpenShift Service on AWS (ROSA) helps teams streamline data-in-motion across the enterprise, support real-time decision-making, and enhance overall business operations. This joint pattern enables organizations to meet strict security standards and compliance requirements while freeing IT teams from complex infrastructure management to focus on business innovation. In this blog, you’ll learn how Confluent Platform operates on ROSA and how this architecture simplifies enterprise event streaming.
Advantages of Red Hat OpenShift Service on AWS (ROSA)
When you deploy on ROSA, you operate on a fully managed application platform jointly managed and operated directly by Red Hat and AWS. This approach accelerates deployment timelines, maintains cross-environment consistency, and scales applications. ROSA allows your team to focus on developing event-driven logic while Red Hat and AWS manage the underlying OpenShift cluster operations, control planes, and cloud infrastructure.
Deploying Confluent Platform via Confluent for Kubernetes (CFK)—a certified Red Hat OpenShift operator—allows teams to manage Kafka and its surrounding stack as native Kubernetes custom resources. The combination of ROSA’s managed container foundation and CFK’s declarative automation helps organizations scale enterprise streaming with maximum reliability and minimal IT overhead.
What is ROSA?
Red Hat OpenShift Service on AWS (ROSA) is a fully managed application platform designed to let your team focus on what really matters: deploying applications and accelerating innovation.
By offloading cluster lifecycle management entirely to Red Hat and AWS, ROSA frees up your resources so you can deliver business value instead of managing undifferentiated infrastructure. Because it is jointly engineered and supported by both companies, ROSA lives natively within the AWS console. This integration reduces complexity while giving you immediate access to a massive ecosystem of native AWS services and toolsets.
The Hosted Control Plane (HCP) Advantage
Today, ROSA uses hosted control planes (HCP) as its default architecture. Under this model, Red Hat runs the control plane for you, meaning you no longer have to manage—or pay for—dedicated control-plane nodes.
This architecture delivers two massive benefits for your bottom line and your security posture:
- Slashed Cloud Costs
- Zero control-node overhead: Offloading the control plane to Red Hat immediately eliminates the need to pay for dedicated EC2 control infrastructure.
- Intelligent autoscaling: The Red Hat build of Karpenter drives these savings even further through pod-aware autoscaling, automatically right-sizing compute resources and consolidating underutilized nodes.
- Spot Instance optimization: Karpenter also manages AWS Spot Instances to offer up to 90% savings over On-Demand pricing for fault-tolerant workloads. It even includes automated fallback protection to guarantee uptime if Spot Instances are reclaimed.
- Enterprise-Grade Security and Compliance
- Architecture and Access: ROSA HCP secures your environment through isolated control planes and standardized AWS managed policies that enforce least-privilege identity access.
- Customer-Approved Access: For tightly regulated environments, this optional feature gives you strict, granular control over Site Reliability Engineering (SRE) support permissions.
- Out-of-the-box compliance: The platform is fully compliant with stringent industry standards, including PCI-DSS, and SOC 2. ROSA is also HIPAA enabled.
Confluent on ROSA (HCP)
Why Confluent Platform on ROSA
The value of this pattern is not “Kafka on Kubernetes” in the abstract. It is enterprise streaming on the OpenShift operating model your platform teams already trust, with AWS underneath and Confluent’s automation on top.
First: CFK turns Confluent Platform into declarative infrastructure. Instead of hand-wiring brokers, Controllers, certificates, and upgrades, operators define desired state with Kubernetes custom resources and let CFK handle deployment, scaling, rack awareness, and recovery behaviors. That aligns streaming operations with the GitOps and Infrastructure-as-Code practices natively built into and supported by ROSA as a managed application platform. Combined with ROSA’s turnkey platform—jointly managed and operated by Red Hat and AWS—platform teams spend less time babysitting infrastructure plumbing and more time delivering reliable event streams. See the CFK overview and ROSA overview.
Second: ROSA’s enterprise-grade security and access controls travel natively with the workload. On ROSA, CFK integrates with built-in OpenShift security guardrails (like Security Context Constraints) while leveraging AWS-native capabilities—such as AWS PrivateLink, AWS Key Management Service (KMS) encryption, fine-grained IAM roles, and secure ROSA ingress controls. For regulated and hybrid estates, this creates a unified control surface for identity, networking, encryption, and audit logging across both application containers and event streams, rather than bolting Kafka onto an isolated security island.
Third: the pattern preserves operational consistency across hybrid and multi-cloud environments. ROSA provides a unified, enterprise-grade on-ramp for teams building and deploying applications on AWS while maintaining standard Kubernetes APIs, tools, and practices (AWS ROSA FAQ, Red Hat ROSA). Layering Confluent Platform via CFK extends that consistency to data in motion: the same certified operator story, the same Kubernetes-native lifecycle, and the same path from cluster to streaming applications—whether the immediate goal is payments, customer experience, or internal event-driven modernization. Certification and Operator Lifecycle Manager discovery further reduce adoption friction (Confluent + Red Hat announcement).
Concrete takeaways for readers:
- Operate streaming like any other OpenShift workload — CFK CRDs + GitOps, not bespoke broker runbooks.
- Keep enterprise OpenShift security and networking — SCC-aware planning and Route-based external access where appropriate.
- Let ROSA own more of the platform burden — managed OpenShift on AWS with joint support, so teams focus on streams and apps.
- Standardize hybrid OpenShift estates — same operator-certified path for Confluent Platform wherever you run OpenShift.
When to run Confluent Platform on ROSA
This pattern fits when you need enterprise event streaming under OpenShift governance on AWS—especially when platform standardization, operational consistency, or regulatory control of the streaming tier are primary drivers.
When self-managed Confluent Platform is the right fit. For many teams, Confluent Cloud is the fastest path to streaming. Confluent Platform on ROSA is the deliberate choice when the streaming tier must live inside your own OpenShift governance and AWS account—for data residency and sovereignty, tightly regulated or restricted-network environments, full control of deployment topology and networking, or simply because event streaming has to sit on the same platform standards you already enforce for every other workload. Self-managed does not mean unmanaged: CFK and ROSA absorb most of the day-2 operational burden, as described above.
Financial services (including real-time payments). Banks and payment processors use streaming to power initiation-to-settlement style flows, risk and exception scoring, customer 360, and operational telemetry. Confluent Platform on ROSA lets FSI platform teams place the payments event backbone on the same OpenShift standards they already apply to customer-facing and core-adjacent apps—useful when control of deployment topology, networking, and operational policy is non-negotiable.
Healthcare and life sciences. Clinical and operational systems generate continuous events—admissions, orders, device signals, claims touchpoints. Organizations standardized on OpenShift often need a streaming layer that inherits the same security posture and change-management practices; CP on ROSA is a natural fit for event-driven care workflows and analytics pipelines that must stay within enterprise platform boundaries.
Telecommunications. Network and customer systems produce high-volume telemetry, usage records, and fraud signals. Telcos that run OpenShift at scale benefit from CFK’s automated lifecycle for Kafka while keeping ROSA’s managed OpenShift operations model for the platform underneath.
Retail and omnichannel commerce. Inventory position, orders, price updates, and customer interactions are inherently event-driven. Retailers moving container platforms to AWS with ROSA can add Confluent Platform as the real-time fabric for inventory sync, personalization triggers, and supply-chain visibility—without introducing a separate operations silo.
Enterprise platform standardization (horizontal). Many organizations have already chosen OpenShift as the enterprise application platform. For them, the “when” is simple: when event streaming becomes a first-class platform capability—shared topics, schemas, connectors, and stream processing—alongside the rest of the portfolio. CP on ROSA is the AWS expression of that standard.
Recap
Why this matters now. With Confluent and Red Hat sitting under the same corporate roof, Confluent Platform on ROSA will likely see increased strategic alignment and collaboration. For teams standardizing on OpenShift, this is a durable foundation both platforms can now invest in together.
Confluent Platform on ROSA brings together three ideas that matter to joint Confluent, Red Hat and AWS audiences: enterprise data in motion (Confluent Platform), Kubernetes-native automation (Confluent for Kubernetes), and managed OpenShift on AWS . The result is a pattern for running production streaming where your application platform already lives—declaratively operated, OpenShift-aligned, and ready for industries that treat real-time events as core infrastructure.
If you are evaluating this architecture, start with the public documentation and examples below, then engage your Confluent and Red Hat teams to map sizing, networking, and security requirements to your estate.
Call to action
Confluent
- Confluent Platform overview
- Deploy and manage Confluent Platform with CFK
- Plan a CFK deployment (incl. OpenShift SCC guidance)
- Deploy CFK (incl. OpenShift OperatorHub path)
- Configure OpenShift Routes for CFK
- Confluent Platform for Apache Flink
- confluentinc/confluent-kubernetes-examples
- Confluent for Kubernetes certified on OpenShift (blog)
- Deploy Kafka on Kubernetes with Confluent and OpenShift (blog)
Red Hat / AWS / ROSA