IBM Bob Use Case · Arrow Experience Center

Quantum-Safe POC Environment

Complete deployment of enterprise quantum-safe cryptography evaluation infrastructure in 23 minutes — compared to 6–8 weeks for external delivery. Immediate strategic advantage for IBM and Arrow Business Partners.

IBM Guardium Crypto Manager IBM Quantum Safe Remediator Red Hat OpenShift IBM Fusion HCI Frank Welder · Arrow ECS

The Numbers

23 min
Full Deployment
4
Virtual Machines
100%
Automated
95%
Time Savings

The Challenge

External POC environments for quantum-safe cryptography evaluation typically require 6–8 weeks for delivery — delaying critical evaluations and slowing the sales cycle. IBM and Arrow Business Partners needed the ability to spin up a complete, production-realistic evaluation enclave on demand.

Bob automated the entire process: infrastructure provisioning, OS deployment, application installation, security integration, and DNS registration — all from the IBM Storage Fusion HCI cluster running Red Hat OpenShift Virtualization at the AEC.

The Four-VM Enclave

VM 1 — Core Engine
GCM Sentinel
IBM Guardium Cryptographic Manager v2.0.1 — enterprise key management and quantum-safe cryptography evaluation platform.
vCPU: 24 cores · RAM: 48 GB Storage: 150 GB · OS: RHEL 9.4+ K8s: K3s v1.33+
VM 2 — Transport Layer
QSR Proxy
IBM Quantum Safe Remediator v1.1.x — data transport interception and quantum-safe protocol adaptation with KMIP mTLS passthrough.
vCPU: 8 cores · RAM: 64 GB Storage: 100 GB · OS: RHEL 9.4+ Docker: v25.0.3+
VM 3 — Analysis Platform
QSE Workstation
IBM Quantum Safe Explorer v2.x — cryptographic library analysis and post-quantum readiness assessment for client codebases.
vCPU: 8 cores · RAM: 16 GB Storage: 250 GB · OS: Windows 11 Pro IDE: VS Code + QSE Extension
VM 4 — Secure Access
Bastion Jump Server
Secure jump host with documentation hosting, file sharing (NFS/CIFS), centralized logging, and controlled ingress to the enclave.
vCPU: 16 cores · RAM: 32 GB Storage: 500 GB · OS: RHEL 9.4+ Services: HTTP, NFS, CIFS

Deployment Timeline

1

Infrastructure Validation (2 min)

Verified OpenShift cluster health, validated resource pools, confirmed IBM License Service operational.

2

VM Provisioning (5 min)

Created 4 VMs with exact specifications — resource allocation, networking, storage, namespace assignment.

3

OS Deployment (8 min)

RHEL 9.4+ instant-cloned onto 3 Linux VMs; Windows 11 ISO import initiated for the QSE workstation.

4

Security Configuration (5 min)

Active Directory domain join, QRadar SIEM log streaming configured, mTLS passthrough routes established for KMIP services.

5

Application Deployment (3 min)

K3s installed, GCM trial sizing deployed, QSR proxy configured, bastion documentation and file-sharing services started.

Technology Stack

Infrastructure

  • IBM Storage Fusion HCI v2.11.0
  • Red Hat OpenShift v4.16.43
  • OpenShift Virtualization (KubeVirt)
  • 80 vCPU · 314 GiB RAM cluster

Quantum-Safe Suite

  • IBM Guardium Crypto Manager
  • IBM Quantum Safe Remediator
  • IBM Quantum Safe Explorer
  • KMIP with mTLS passthrough

Security

  • Active Directory Integration
  • QRadar SIEM Logging
  • Role-Based Access Control
  • Audit Trail Automation

Orchestration

  • Kubernetes (K3s)
  • Cloud-init Automation
  • rsync over SSH
  • Automated DNS Registration

Outcomes

23-minute deployment vs 6–8 week external delivery
Full 4-VM enclave — GCM, QSR, QSE, bastion
Enterprise AD + QRadar SIEM integration from day one
KMIP mTLS passthrough for production-realistic evaluation
Repeatable template for future quantum-safe POCs
Immediate client engagement — same day as request

See Q-Forge in depthThe full GCM 2.0.1 documentation site — installation, configuration, operations.