1. Images & Charts
  2. apache-kvrocks-fips
apache-kvrocks-fips

apache-kvrocks-fips

Data
Fips
Stig
Updated 23 hours ago

Apache Kvrocks-FIPS Overview

Secure your stack with a FIPS-validated, hardened Apache Kvrocks image freshly-built by Minimus. Minimus images always include the most up-to-date package version for all packages and dependencies contained in the image.


Apache Kvrocks is a distributed key-value NoSQL database that uses RocksDB as its storage engine and is compatible with the Redis protocol. Use it as a cost-efficient, persistent alternative to in-memory stores for large datasets that exceed available RAM. Use this image when you need to meet the requirements for FIPS-validated cryptographic protection.


FIPS 140-3 Certification

This image is FIPS-validated to ensure its cryptographic operations meet the Federal Information Processing Standards (FIPS) required for secure government and regulated environments. Its core cryptographic modules are validated under the NIST Cryptographic Module Validation Program (CMVP) and comply with the FIPS 140-3 standard.

To verify that the FIPS 140-3 provider is configured and active, follow the instructions in the FIPS compliance tab.


Try It Out

Take the Minimus Apache Kvrocks-FIPS image for a test run:

docker run --rm \
  -p 6666:6666 \
reg.mini.dev/apache-kvrocks-fips

This command will start the Kvrocks server container and map port 6666/TCP in the Kvrocks container to port 6666/TCP on the localhost.

We can test the connection to the Kvrocks server either from another Kvrocks container (as a client) or from our host machine.

Option 1: From another Kvrocks container

In another terminal, run the following command to start and enter a client container:

docker run --rm --network host -it --entrypoint /bin/bash reg.mini.dev/apache-kvrocks-fips

Once you're inside the container (you'll see a prompt like bash-5.2$), run the following command to retrieve server details from the Kvrocks instance using the Redis-compatible CLI:

redis-cli -h 127.0.0.1 -p 6666 info server

You should get a response something like:

# Server
kvrocks_version:2.16.0
redis_version:7.0.0
kvrocks_mode:standalone
tcp_port:6666
...

Option 2: From your host machine

In another terminal, install the Redis command-line tools using:

sudo apt install redis-tools

Once the tools are installed, you can run redis-cli commands to interact with your Kvrocks server container. For example, to view server details, run:

redis-cli -h 127.0.0.1 -p 6666 info server

You should receive output similar to:

# Server
kvrocks_version:2.16.0
redis_version:7.0.0
kvrocks_mode:standalone
tcp_port:6666
...

Technical Considerations

The Apache Kvrocks-FIPS image provided by Minimus is a FIPS-validated, slim, security-hardened alternative to the public image from Docker Hub. The images are largely interchangeable, with a few differences as noted below.

Apache Kvrocks-FIPS built by Minimus:

  1. Runs as non-root by default, matching the public image's non-root default of user 999.
  2. Listens on port 6666/TCP by default but does not expose the port. The public image listens on and exposes the same port by default.
  3. The image does not expose a volume by default. The public image exposes the volume /var/lib/kvrocks.
  4. Drill down on the version specification tab to see the default user, listening ports, entrypoint, volumes, environment variables, etc.

The Payoff

A hardened, minimal image that will remain more secure for the long run and accrue vulnerabilities at a slower rate.


Terms & Info

Trademark

This catalog is published by Minimus. All product names, logos, and marks, other than those belonging to Minimus, shown are owned by their respective rights holders and appear here only to identify the open source software each image contains. Minimus claims no ownership of those marks and implies no affiliation with, endorsement by, certification by, or sponsorship by any rights holder.

Disclaimer

Images are provided "as-is" without warranty of any kind. "Hardened" refers to the security configuration applied at the time of build and does not constitute a guarantee of ongoing security or absence of vulnerabilities. The free tier is provided without support, SLA, or guaranteed patching timelines. Security updates may be applied to paid subscriptions before or instead of free tier images. By pulling or using any image you agree to our Terms of Use.