Encrypt underlying host storage across cluster nodes

Encrypting the root and ephemeral file systems on cluster nodes protects container runtime data, logs, and caches against physical drive theft or cloud snapshot leaks. Red Hat OpenShift Container Platform supports TPM-backed encryption and Network-Bound Disk Encryption (NBDE) with Tang servers, each with different key escrow and availability trade-offs.