About Kubernetes KMS v2 encryption
Kubernetes KMS v2 uses external Key Management Services to encrypt etcd data and centralize key management.
Kubernetes KMS v2 provides:
-
Customer-managed encryption keys that never leave the external KMS
-
Centralized key management and auditing
-
Regulatory compliance support
Encrypted resources
When you enable KMS encryption, Red Hat OpenShift Container Platform encrypts the following sensitive resources in etcd:
-
Secrets
-
ConfigMaps
-
Routes
-
OAuth access tokens
-
OAuth authorize tokens
|
|
Resource types, namespaces, and object names are not encrypted. |
Additional resources