About Kubernetes KMS v2 encryption

Kubernetes KMS v2 uses external Key Management Services to encrypt etcd data and centralize key management.

Kubernetes KMS v2 provides:

  • Customer-managed encryption keys that never leave the external KMS

  • Centralized key management and auditing

  • Regulatory compliance support

Encrypted resources

When you enable KMS encryption, Red Hat OpenShift Container Platform encrypts the following sensitive resources in etcd:

  • Secrets

  • ConfigMaps

  • Routes

  • OAuth access tokens

  • OAuth authorize tokens

Note

Resource types, namespaces, and object names are not encrypted.