Insights · OpenShift practice · Issue I, MMXXVI.

OpenShift on the public cloud, read per provider.

Four managed faces, one self managed alternative on every cloud, and four invoicing paths. The audit notice, the support agreement, and the buyer side leverage all change per provider.
By The Buyer-Side Desk, an independent advisory practice. 190+ engagements, $180M+ recovered. Published Updated
Abstract

OpenShift on the public cloud carries four managed faces and a self managed alternative on every hyperscaler. ROSA on AWS, ARO on Azure, OpenShift Dedicated, and IBM Cloud for OpenShift each have their own invoicing path, their own support boundary, and their own audit posture. The buyer side reading at the renewal table treats the cloud provider line and the Red Hat line as two contracts on the same workload, signs neither without reading both, and reads the self managed alternative against the managed line on the same cloud.

§ 1

Four managed faces, and one alternative.

OpenShift on the public cloud takes one of five shapes in 2026. Four of them are managed services where Red Hat or the cloud provider operates the cluster on the buyer's behalf. The fifth is self managed OpenShift, where the buyer installs and operates Red Hat OpenShift Container Platform on the cloud provider's infrastructure as just another workload1.

Red Hat OpenShift Service on AWS, known as ROSA, is jointly operated by AWS and Red Hat. Azure Red Hat OpenShift, known as ARO, is jointly operated by Microsoft and Red Hat and invoiced through Microsoft. Red Hat OpenShift Dedicated runs on Google Cloud and AWS under Red Hat operational responsibility. IBM Cloud for Red Hat OpenShift runs on IBM Cloud under IBM operational responsibility. Self managed OpenShift runs on any of these clouds under the buyer's operational responsibility.

The choice between managed and self managed is rarely a clean either or. Most enterprise estates in 2026 carry one managed flavour on the cloud where the primary workload runs and self managed OpenShift on the cloud where the secondary workload runs, with one or more clusters of each across the estate. The reading at the renewal table separates the managed line from the self managed line and treats them as two readings, not one.

§ 2

ROSA on AWS, jointly delivered.

ROSA is jointly engineered and jointly supported by AWS and Red Hat. The buyer purchases ROSA through the AWS console and the cluster is operated under shared responsibility between AWS for the underlying infrastructure and Red Hat for the OpenShift platform itself. Billing flows through AWS and consolidates with the buyer's AWS spend. Support cases route through both vendors, with a clean escalation path between them2.

The licensing on ROSA reads as a per cluster hourly rate plus the AWS infrastructure consumption underneath. The hourly rate covers the OpenShift platform itself. The AWS infrastructure carries the standard EC2, EBS, ELB, and network rates that any AWS workload carries. A buyer who reads only the ROSA line and not the AWS infrastructure line underestimates the cluster cost by a multiple, because the infrastructure is typically the larger of the two on a steady state cluster.

Annual commitments on ROSA produce material discounts on the platform rate. The discounts apply to the OpenShift portion of the line and do not extend to the underlying AWS infrastructure. The AWS infrastructure is negotiated through the AWS enterprise agreement, separately, with its own commitment mechanics and its own discount structure. The two negotiations happen on different cycles with different counterparties even when both lines apply to the same cluster.

§ 3

ARO on Azure, invoiced through Microsoft.

Azure Red Hat OpenShift is jointly engineered and operated by Microsoft and Red Hat, with the buyer relationship sitting on Microsoft's side of the contract. The cluster appears as an Azure resource, the billing flows through the Azure invoice, and the buyer's Microsoft Enterprise Agreement covers the ARO line alongside other Azure consumption. Support routes through Microsoft with escalation to Red Hat for platform layer issues.

The reading at the renewal table on ARO is therefore a Microsoft Enterprise Agreement reading first and a Red Hat reading second. The Red Hat line is embedded in the Azure invoice and does not surface as a separate Red Hat negotiation in most quarters. The Microsoft renewal cycle absorbs the ARO line into the broader Azure commit. A buyer who runs ARO and self managed OpenShift on Azure side by side has two readings: the ARO line through Microsoft and the self managed line directly with Red Hat.

The audit posture on ARO sits primarily on the Microsoft side, because the cluster is a Microsoft delivered service. Red Hat's direct audit reach on an ARO cluster is narrower than on a self managed cluster on Azure infrastructure. The structural consequence is that an enterprise estate with ARO as the OpenShift posture on Azure carries less Red Hat audit exposure on the Azure clusters than the same estate would carry on self managed OpenShift across the same Azure infrastructure. The trade off is that the buyer carries the ARO line at the Azure invoice rate, which is rarely the lowest aggregate cost on the same workload3.

§ 4

OpenShift Dedicated, and IBM Cloud for OpenShift.

Red Hat OpenShift Dedicated is the Red Hat operated managed service on Google Cloud and AWS, distinct from the jointly operated ROSA on AWS. OpenShift Dedicated is invoiced through Red Hat directly and runs on cloud infrastructure that the buyer either provides through their own cloud account or that Red Hat provides on the buyer's behalf. The operational responsibility sits with Red Hat. The infrastructure responsibility sits with the buyer if the cloud account is the buyer's.

The licensing on OpenShift Dedicated reads as a Red Hat subscription with cluster sizing parameters and an annual term. The infrastructure underneath sits on the buyer's cloud account and is invoiced separately by the cloud provider. The reading at the renewal table runs through Red Hat for the OpenShift Dedicated line and through Google Cloud or AWS for the infrastructure line, with the two lines covering the same cluster.

IBM Cloud for Red Hat OpenShift is operated by IBM on IBM Cloud and is invoiced as part of the IBM Cloud relationship. The line is sized against the cluster footprint and the IBM Cloud infrastructure consumption underneath. The audit posture sits with IBM as the operating partner and with Red Hat for the platform layer. The structural reading is similar to ARO on Azure, with IBM in the operator role rather than Microsoft.

The buyer side comparison across the four managed faces turns on the cloud where the workload sits, the existing enterprise agreement with that cloud, the operational preference between joint and Red Hat sole operation, and the comparative infrastructure pricing across the candidate clouds for the workload pattern. None of the four faces is uniformly the cheapest. The right choice is workload by workload and cloud by cloud, and the reading at the renewal table reads each cluster on the right contract path.

Fig. 4.1 · OpenShift on the public cloud · four managed faces and the self managed alternativeRHLA · 2026 Q2
Item Frequency Reading
ROSA on AWSJoint AWS and Red HatAWS invoice plus EA
ARO on AzureJoint Microsoft and Red HatAzure invoice through Microsoft EA
OpenShift DedicatedRed Hat operated, GCP or AWSRed Hat invoice plus cloud infra
IBM Cloud for OpenShiftIBM operated, IBM CloudIBM Cloud invoice
Self managed OpenShiftAny hyperscalerRed Hat subscription plus cloud infra
Practice observation of OpenShift estates running across multiple clouds in 2026. The same enterprise rarely runs all five faces at once; most run two or three. The contractual reading separates the OpenShift line from the cloud infrastructure line in every case.
§ 5

Self managed OpenShift, on every cloud.

Self managed OpenShift on the public cloud runs as a standard Red Hat OpenShift Container Platform subscription against worker core count on cloud infrastructure that the buyer provides through their own cloud account. The licensing model is the same as on premises self managed OpenShift, with the cluster footprint sized per core and the support tier applied across the cluster lifecycle. The cloud infrastructure is invoiced separately by the cloud provider.

The self managed posture carries the full Red Hat audit surface because the buyer is the cluster operator. The cluster inventory, the cluster sizing, the cluster lifecycle, and the cluster scope are all the buyer's responsibility to track. A self managed cluster on AWS that grows from sixteen worker cores to forty across a contract term carries the audit exposure of that growth in the same way a self managed cluster on bare metal would carry it.

The buyer side trade off between self managed and managed on the same cloud is between the per cluster cost of the managed line and the operational cost of carrying the cluster lifecycle in house. The Red Hat line on self managed often prices below the managed line on the same cloud at comparable scale; the operational overhead may close the gap or reverse it depending on the platform team's posture. The reading at the renewal table compares the two on the cluster set the buyer actually operates.

We had ROSA on AWS for the primary estate and self managed OpenShift on Azure for a regulated workload. The reading separated the AWS hourly line from the Azure subscription line and renegotiated each on its own cycle. Treating the two as one estate at the renewal table had been costing twelve percent of the aggregate cloud OpenShift line.
Testimony of record · Head of Cloud Engineering · financial services
§ 6

Reading the cloud line at the renewal table.

The renewal table on OpenShift across the public cloud is rarely one conversation. It is two or three, one per provider, plus the underlying enterprise agreement renewal on each cloud. The buyer who treats the OpenShift estate as a single Red Hat conversation misses the savings that sit on the Microsoft, AWS, Google Cloud, or IBM Cloud side of the same cluster.

The discipline at the renewal table reads each cluster against its contract path. ROSA clusters read against the AWS enterprise agreement and the ROSA hourly rate. ARO clusters read against the Microsoft enterprise agreement. OpenShift Dedicated reads through Red Hat with the cloud infrastructure as a separate line. IBM Cloud for OpenShift reads through IBM Cloud. Self managed clusters read as standalone Red Hat subscriptions with cloud infrastructure on the side. Five clusters across the same workload can carry five different commercial conversations.

The aggregate posture turns on which workload belongs on which cloud and which face. The conversation at the audit notice is narrower: it reads the cluster against the contract it actually carries, and it does not invite scope across faces. An audit defense on a ROSA cluster is a different conversation from an audit defense on a self managed Azure cluster, with different counterparties and different documentary requirements. For the broader cloud posture reading, see the OpenShift practice hub and the edition reading. For the engagement protocol, see contact.

Notes & references

  1. 1. Red Hat OpenShift product family page, accessed across 2025 and 2026. The five faces of OpenShift on the public cloud are documented across the product pages for ROSA, ARO, OpenShift Dedicated, IBM Cloud for Red Hat OpenShift, and Red Hat OpenShift Container Platform self managed installations.
  2. 2. ROSA jointly operated service overview, AWS and Red Hat documentation. The hourly and annual commitment structures, infrastructure billing through AWS, and joint support escalation path are documented across the AWS and Red Hat product pages.
  3. 3. ARO managed service overview, Microsoft and Red Hat documentation. The Microsoft Enterprise Agreement absorbs the ARO line for billing and for renewal purposes. Practice observation across ARO heavy estates in the trailing twelve months shows the Red Hat audit surface on ARO is materially narrower than on self managed OpenShift on Azure infrastructure.
  4. 4. Concession bands referenced throughout reflect the practice's observation across signed contracts in the trailing twelve months on cloud OpenShift renewals across all four managed faces and the self managed alternative, not list prices and not initial vendor quotes.
  5. 5. All figures are net of fees and verified against signed contract deltas. The eighty two percent audit exposure reduction referenced in practice marginalia is the trailing twelve month average across defenses settled, not a cloud OpenShift specific figure.

Preparing a response? The practice keeps a one-page Red Hat audit response checklist — what to acknowledge, what to preserve, and what not to volunteer in the first fourteen days after the letter arrives.

§ 7 · Engagement

Read the cloud line per provider.

Two analyst calls. No fee. We separate the managed line from the self managed line, read each cluster against its actual contract path, and tell you which face fits which workload on the renewal as it stands.