2.8 Encrypt etc

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

ETCD is not enabled by default; enabling it can provide an additional layer of protection.

Rationale:

You can enable etcd encryption for your cluster to provide an additional layer of data security. For example, it can help protect the loss of sensitive data if an etcd backup is exposed to the incorrect parties.

Impact:

With encrpytion on etcd the following contents are encrypted at rest

Secrets

Config maps

Routes

OAuth access tokens

OAuth authorize tokens

Solution

Modify the API Server Object

oc edit apiserver

Set the encryption field type to aescbc:

spec: encryption: type: aescbc

Save the file to apply the changes.

The encryption process starts. It can take 20 minutes or longer for this process to complete, depending on the size of your cluster.

Default Value:

By default ETCD is not encrypted

See Also

https://workbench.cisecurity.org/files/4260