Skip to main content
Version: 2.15.0

Shared responsibility model

Deployment options

Cloud service provider managed Kubernetes

  • Deploys Halo artefacts including Helm charts and container images into a Customer managed Kubernetes cluster hosted in public, private, or government cloud environments such as Azure, AWS, or Oracle.
  • Uses native cloud PaaS and SaaS services for storage and key or secret management and is validated internally against each supported platform.
  • Customers typically pull Halo artefacts directly from the Glasswall container registry at glasswallhub.azurecr.io.
  • Artefacts are preconfigured for each supported cloud platform.
  • Installation guidance is available in the Glasswall documentation.

On prem customer managed Kubernetes

  • Deploys Halo artefacts into a Customer managed Kubernetes cluster hosted in an on prem environment such as Rancher Enterprise, VMware Tanzu, or Red Hat OpenShift.
  • Requires integration with Customer managed storage and key or secret management services.
  • Customers typically pull artefacts from glasswallhub.azurecr.io.
  • Some environments may require additional configuration.
  • General deployment guidance is available in the Glasswall documentation.
  • Due to platform variability, professional services support is commonly required during deployment.

On prem customer managed virtual machine single node

  • Deploys a Halo single node VHD or OVA into a Customer virtualisation environment such as VMware.
  • Artefacts are typically downloaded via Kiteworks.
  • Delivered preconfigured, with scalability limited by single virtual machine resources.
  • Scaling or high availability requires Customer managed networking such as load balancing.
  • Installation guidance is available in the Glasswall documentation.
  • While simpler than Kubernetes based deployments, targeted support is often required during installation.

Shared responsibility matrix

ResponsibilityCloud service provider managed KubernetesOn prem Customer managed KubernetesOn prem Customer managed virtual machine
Access to deployment assetsGlasswallGlasswallGlasswall
CDR functionalityGlasswallGlasswallGlasswall
Technical and compliance documentationGlasswallGlasswallGlasswall
Application logging accuracy and guidanceGlasswallGlasswallGlasswall
Helm chart configuration and testingGlasswallGlasswall and CustomerGlasswall
Deployment documentation and scriptsGlasswallCustomerGlasswall
Infrastructure integration guidance and scriptsGlasswallCustomerCustomer
Integration with business applicationsCustomerCustomerCustomer
Identity providers, credentials, and cluster integrationCustomerCustomerCustomer
External network integration including TLS and securityCustomerCustomerCustomer
External storage configuration and securityCSP and CustomerCustomerCustomer
Infrastructure and cluster monitoring and loggingCSP and CustomerCustomerCustomer
Infrastructure access, resiliency, and availabilityCSPCustomerCustomer
Host operating system security and hardeningCSP and CustomerCustomerGlasswall