We are proud to announce that Isovalent Networking for Kubernetes is now officially certified for Red Hat OpenShift Hosted Control Planes (HCP). This milestone makes us the first and only CNI to achieve HCP certification, further strengthening our position as the enterprise choice for secure and scalable Kubernetes networking. What Is a Hosted Control Plane (HCP)? A Hosted Control Plane is a modern, cloud‑native architecture in which the control plane components of an OpenShift cluster, such as the API server, controller manager, etcd and scheduler, are decoupled from the worker nodes and managed as pods on a separate management cluster. These components are not tied to dedicated VMs or physical servers for each cluster, but instead run on an existing “management” or “hosting” cluster, managed by HyperShift (the underlying project that provides this capability) or the multicluster engine for Kubernetes Operator. This architecture offers several benefits: Cost efficiency: hosted control planes can run many clusters on fewer nodes by leveraging Kubernetes‑native workloads instead of standalone control plane infrastructure Faster provisioning: control planes spin up quickly since they are pods, enabling faster cluster delivery Improved isolation and security: decoupling control and data planes enhances separation, reducing the risk of credential exposure and inadvertent infrastructure changes Simplified operations at scale: the management cluster centralizes cluster lifecycle tasks, enabling more streamlined upgrades, observability and incident response An HCP setup enables multi‑cluster scale, reduces operational footprint, and boosts manageability without compromising on control or performance. Why This Certification Matters for Enterprises What does the Red Hat Certification consist of? OpenShift Hosted Control Planes represent the next step in Red Hat’s platform evolution, designed to improve cluster efficiency, reduce operational overhead, and accelerate the adoption of multi-cluster architectures. The certification of this offering ensures a standardised testing between container networking offerings and the Red Hat platform for reliability when deployed together. With this certification, customers running OpenShift in HCP environments can confidently rely on Isovalent Networking for Kubernetes as their networking foundation. Why does this matter? Certification ensures that our solution has been validated by Red Hat engineers against their latest architecture, providing peace of mind that deployments will be supported, reliable, and future-proof. For organizations already standardizing on OpenShift, this unlocks consistent networking, observability, and security across both traditional and hosted control plane clusters. Isovalent and Red Hat engineering teams collaborate together across a number of areas, including the creation of this particular certification, to help ensure joint customers have confidence in both organizations' software. Enterprise Value of Isovalent Networking for Kubernetes Operational Efficiency: Built on eBPF, Isovalent Networking for Kubernetes removes layers of legacy complexity, delivering high performance and lower infrastructure costs. Advanced Security: Zero-trust segmentation with identity-aware network policies, encryption, and runtime observability ensures compliance across regulated industries. Deep Visibility: Hubble observability provides real-time flow and policy insights that can be visualized in any platform of choice, helping teams diagnose and resolve issues faster. Future-Ready Networking: Features such as kube-proxy replacement, advanced load balancing, and multi-cluster connectivity prepare enterprises for hybrid and cloud-native expansion. Streamlined Installation with Cilium Lifecycle Operator Alongside certification, we have published detailed installation instructions for OpenShift HCP environments. These leverage the Cilium Lifecycle Operator (CLife) to simplify deployment and upgrades across diverse OpenShift topologies including Installer-Provisioned Infrastructure, Agent-based installations, Red Hat Advanced Cluster Management, and now Hosted Control Planes. For HCP users, our documentation provides clear steps to configure IPAM ranges, enable kube-proxy replacement, and integrate with Red Hat’s supported architecture. Platform owners also benefit from out-of-the-box connectivity tests, metrics, and observability. To see this in action, we recorded a demo showing Isovalent Networking for Kubernetes running on the HCP management cluster and then creating a new HCP cluster with Cilium installed. The walkthrough highlights how simple and consistent the experience is across both management and workload clusters. Confidence Through Certification The official Red Hat Certified OpenShift CNI Plug-ins page now lists Isovalent Networking for Kubernetes as certified for Hosted Control Planes. Currently Isovalent are the only 3rd Party CNI listed with this support, providing highly scalable eBPF powered networking, security and observability for Red Hat OpenShift environments. This validation underscores the joint work carried out between Red Hat and our teams, ensuring that Isovalent continues to be the most advanced, trusted, and enterprise-ready networking solution for OpenShift. Where This Fits in the Red Hat Ecosystem With this new certification for OpenShift Hosted Control Planes (HCP), Isovalent Networking for Kubernetes extends its coverage across the Red Hat OpenShift portfolio. Organizations can now deploy Isovalent Networking for Kubernetes with confidence on: Red Hat OpenShift Hosted Control Planes (HCP) – certified and supported Red Hat OpenShift on AWS (ROSA) – fully supported for hybrid cloud deployments Traditional OpenShift clusters – across on-premises and cloud infrastructure This breadth of support ensures that no matter how enterprises choose to consume OpenShift, through managed services like ROSA, hosted control planes, or self-managed clusters, Isovalent delivers consistent networking, observability, and security. Ready to take the next step? Contact our sales team to discuss how Isovalent Networking for Kubernetes can help your organization, or join one of our upcoming webinars to see our software in action and learn directly from our experts.