Skip to content

Optional Root AMI Encryption#6

Open
icereval wants to merge 1 commit into
mgoodness:developfrom
icereval:feature/encrypt-volumes
Open

Optional Root AMI Encryption#6
icereval wants to merge 1 commit into
mgoodness:developfrom
icereval:feature/encrypt-volumes

Conversation

@icereval

@icereval icereval commented Jan 29, 2017

Copy link
Copy Markdown
Contributor

@icereval icereval changed the title Encrypt Volumes Including Root Using Copied AMI Encrypt Volumes and Optional Root AMI Jan 29, 2017
@mgoodness

Copy link
Copy Markdown
Owner

Can we put etcd data volume encryption behind a bool, as with the AMI? It should default to true, but the option makes node-by-node upgrades easier.

@icereval

icereval commented Jan 29, 2017

Copy link
Copy Markdown
Contributor Author

Looks like encrypted root volume's are not working with the latest stable AMI's for CoreOS, more here.

coreos/bugs#1692 (comment)

@mgoodness

mgoodness commented Jan 30, 2017

Copy link
Copy Markdown
Owner

Want to pull the etcd EBS encryption out into its own PR, and hold off the AMI work in the hopes it's addressed upstream?

@icereval

Copy link
Copy Markdown
Contributor Author

Sure, I'll get a PR up tomorrow.

@icereval

Copy link
Copy Markdown
Contributor Author

rebased w/ only ami encryption

@icereval icereval changed the title Encrypt Volumes and Optional Root AMI Optional Root AMI Encryption Jan 31, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants