etcd Secrets Encryption
"apiServerFlags": "--encryption-provider-config=/var/opt/pf9/kube/apiserver-config/encryption-provider.yaml"Cluster creation
mkdir -p /var/opt/pf9/kube/apiserver-config # This directory may be missing in case the node has not been preped using pf9ctl
touch /var/opt/pf9/kube/apiserver-config/encryption-provider.yaml
chown pf9:pf9group /var/opt/pf9/kube/apiserver-config/encryption-provider.yamlapiVersion: apiserver.config.k8s.io/v1
kind: EncryptionConfiguration
resources:
- resources:
- secrets
providers:
- aescbc:
keys:
- name: key1
secret: ZnfoLrhTJFRq3pl4cPrlboH0lsHS33A3axWDl1HKWj8=
- identity: {}Create a cluster with secret encryptions using the Qbert API
Attach the master nodes using Qbert API
Rotating a decryption key
Decrypting all data
Last updated
Was this helpful?
