Skip to main content

PaaS Responsibility Matrix - OpenShift SecNumCloud

Here is the RACI model defining the allocation of responsibilities between the client and Cloud Temple for the use of the OpenShift SecNumCloud PaaS.

Definition of the different roles

Here is a reminder of the different RACI roles:

RoleDescription
(R) Responsible__R__esponsible for executing the process
(A) Accountable__A__ccountable for approving the process execution
(C) Consulted__C__onsulted during the process
(I) Informed__I__nformed of the process results (via tooling, the portal, or messaging)

Initial Setup

ActivityClient RoleCloud Temple Role
Define the overall OpenShift platform architectureCRA
Size the OpenShift platform (number of nodes, resources)CRA
Install and configure the OpenShift platformIRA
Configure the base network for the OpenShift platformIRA
Set up identity and access management for OpenShiftCRA
Define the scaling and high availability strategyCRA

Project and Application Management

ActivityClient RoleCloud Temple Role
Create and manage OpenShift projectsRAC
Deploy and manage applications in OpenShiftRAC
Configure CI/CD pipelinesRAC
Manage container images and registriesRAC

Maintenance and Updates

ActivityClient RoleCloud Temple Role
Update the OpenShift platformIRA
Apply security patches to OpenShiftIRA
Update deployed applicationsRAI
Manage container image updatesRAI

Monitoring and Performance

ActivityClient RoleCloud Temple Role
Monitor OpenShift platform performanceIRA
Monitor application performanceRAI
Manage platform-related alertsIRA
Manage application-related alertsRAI

Security

ActivityClient RoleCloud Temple Role
Manage OpenShift platform securityIRA
Configure and manage pod security policiesRAC
Manage SSL/TLS certificates for the platformIRA
Manage SSL/TLS certificates for applicationsRAC
Implement and manage role-based access control (RBAC)CRA

Backup and Disaster Recovery

ActivityClient RoleCloud Temple Role
Define the backup strategy for the OpenShift platformCRA
Implement and manage platform backupsIRA
Define the backup strategy for applicationsRAC
Implement and manage application backupsRAI
Test disaster recovery procedures for the platformIRA
Test disaster recovery procedures for applicationsRAC

Support and Troubleshooting

ActivityClient RoleCloud Temple Role
Provide Level 1 support for the OpenShift platformIRA
Provide Level 2 and 3 support for the OpenShift platformIRA
Resolve platform-related issuesIRA
Resolve application-related issuesRAC

Capacity Management and Evolution

ActivityClient RoleCloud Temple Role
Monitor platform resource usageIRA
Plan platform capacity evolutionCRA
Implement capacity changesIRA
Manage application evolution and their resourcesRAC

Documentation and compliance

ActivityClient RoleCloud Temple Role
Maintain OpenShift platform documentationIRA
Maintain application documentationRAI
Ensure platform compliance with security standardsIRA
Ensure application compliance with security standardsRAC
Conduct platform auditsIRA
Conduct application auditsRAC

OpenShift Operator Management

OpenShift operators are platform extensions that automate the management of complex applications or services on Kubernetes.

Only Operators from the Certified, Red Hat, and Marketplace catalogs will be offered, provided they are compliant with SecNumCloud requirements and adhere to ecosystem limitations.

The installation, monitoring, and update management of these operators are handled by Cloud Temple, while the Client is responsible for using these operators to manage their workloads.

ActivityClient RoleCloud Temple Role
Operator provisioning in the catalogCIRA
Initial Operator configuration via the MarketplaceCIRA
Operator updatesIRA
Monitoring Operator statusIRA
Operator issue resolutionCIRA
Operator permissions managementCRA
Operator resource management (add/remove)CIRA
Backup of Operator resource dataCIRA
Supervision and monitoring of Operator resourcesCIRA
Restoration of Operator resource dataCIRA
Operator security auditIRA
Red Hat Operators supportIRA
Certified Operators supportIRA
Marketplace Operators supportIRA
License and license contract management for operatorsRAI
Specific support plan management for operatorsRAI

Important note : Only operators declared supported by Cloud Temple and compliant with SecNumCloud are made available. Any uncertified operator or one from an external source will not be supported or validated for use in the environments. The management of licenses and specific support plans for operators from the Red Hat Marketplace catalog is not the responsibility of Cloud Temple. Support management for these operators is de facto delegated to the partner providing the service.


Clarification on Application Support

Application Support (supplementary service):

Application support regarding the development, configuration, management, and maintenance of applications is not the responsibility of Cloud Temple. The scope focuses solely on managing the OpenShift infrastructure and operators. Workload support (deployed applications) and CI/CD pipelines are the responsibility of the client or any designated third-party provider for this task.

ActivityClient RoleCloud Temple Role
Application Support (supplementary service)RAC