forked from rook/rook
When the Ceph cluster runs on PVC and the OSDs are encrypted we can store LUKS's Key Encryption Key inside a Key Management System. Today, Rook only supports HashiCorp Vault: https://www.vaultproject.io/ The CephCluster has now a new "security" field which will plug onto the KMS. Here is an example: security: kms: tokenSecretName: <name of the secret containing a Vault token, used to authenticate> connectionDetails: < a map of strings containing connection information> Refer to the ceph-cluster-crd documentation to lear more. Closes: https://github.com/rook/rook/issues/6105 Signed-off-by: Sébastien Han <seb@redhat.com>