Azure Red Hat OpenShift moves hosted control planes into public preview
The HyperShift-based option removes control-plane compute from customer subscriptions, separates control-plane and worker upgrades, and starts with CLI deployment.
Azure Red Hat OpenShift has opened a public preview of hosted control planes, moving the Kubernetes control plane out of the customer’s Azure subscription and into a dedicated Azure service account managed by Red Hat.
The deployment model is based on the upstream HyperShift project. In the standard Azure Red Hat OpenShift architecture, three dedicated master nodes and the workers run in the customer subscription. The preview removes that control-plane compute and storage footprint from the customer account, leaving the customer to pay for the worker-side compute, networking and storage.
A smaller, decoupled cluster footprint
Red Hat says the minimum infrastructure footprint falls from six nodes to two. It estimates an average infrastructure-cost reduction of as much as fourfold, although that figure comes from a 2026 internal study and will depend on worker sizing and workload shape.
The control plane and worker nodes also gain separate upgrade schedules. Red Hat SREs handle control-plane patching, upgrades and multi-availability-zone placement, while customers can update worker nodes independently. Authentication is limited to managed identities and workload identities; the hosted option does not support service principals.
Red Hat reports provisioning-time reductions of up to 55%. Microsoft’s preview documentation says a typical deployment takes 15 to 20 minutes after the required network, identities, role assignments and encryption resources are prepared.
CLI first, portal later
Preview clusters are created from the command line with an Azure CLI extension or from a Bicep file. The setup is not a one-command abstraction: Microsoft’s guide requires at least 20 cores of quota, a delegated virtual-network integration subnet, a set of user-assigned managed identities and role assignments, and customer-managed encryption for etcd data.
The cluster command exposes public or private visibility for both the API server and application ingress. It also supports public or private Azure Key Vault access for the customer-managed key. A separate command creates the worker node pool after the hosted cluster resource is ready.
Red Hat says an Azure portal workflow is planned for general availability. No GA date is given.
For platform teams, the preview’s main trade is explicit: a smaller customer-side footprint and independently managed control plane in exchange for a newer architecture whose provisioning workflow still exposes substantial Azure identity, networking and key-management detail. Teams evaluating it should validate those prerequisites and preview support limits before treating the cost estimates as a production baseline.
sources
comments · 0