The Numbers
The Challenge
External POC environments for quantum-safe cryptography evaluation typically require 6–8 weeks for delivery — delaying critical evaluations and slowing the sales cycle. IBM and Arrow Business Partners needed the ability to spin up a complete, production-realistic evaluation enclave on demand.
Bob automated the entire process: infrastructure provisioning, OS deployment, application installation, security integration, and DNS registration — all from the IBM Storage Fusion HCI cluster running Red Hat OpenShift Virtualization at the AEC.
The Four-VM Enclave
Deployment Timeline
Infrastructure Validation (2 min)
Verified OpenShift cluster health, validated resource pools, confirmed IBM License Service operational.
VM Provisioning (5 min)
Created 4 VMs with exact specifications — resource allocation, networking, storage, namespace assignment.
OS Deployment (8 min)
RHEL 9.4+ instant-cloned onto 3 Linux VMs; Windows 11 ISO import initiated for the QSE workstation.
Security Configuration (5 min)
Active Directory domain join, QRadar SIEM log streaming configured, mTLS passthrough routes established for KMIP services.
Application Deployment (3 min)
K3s installed, GCM trial sizing deployed, QSR proxy configured, bastion documentation and file-sharing services started.
Technology Stack
Infrastructure
- IBM Storage Fusion HCI v2.11.0
- Red Hat OpenShift v4.16.43
- OpenShift Virtualization (KubeVirt)
- 80 vCPU · 314 GiB RAM cluster
Quantum-Safe Suite
- IBM Guardium Crypto Manager
- IBM Quantum Safe Remediator
- IBM Quantum Safe Explorer
- KMIP with mTLS passthrough
Security
- Active Directory Integration
- QRadar SIEM Logging
- Role-Based Access Control
- Audit Trail Automation
Orchestration
- Kubernetes (K3s)
- Cloud-init Automation
- rsync over SSH
- Automated DNS Registration