Тёмный

Kubernetes Secret Data Encryption at Rest - v1.25 - KMS v2 alpha1 AWS KMS 

Learn with GVR
Подписаться 6 тыс.
Просмотров 2,1 тыс.
50% 1

Опубликовано:

 

21 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 16   
@aniketyadav1622
@aniketyadav1622 Год назад
I just updated the "kube-apiserver.yaml" just like you told in the video. How much downtime is estimated for the nodes to be back?
@learnwithgvr
@learnwithgvr Год назад
2 to 5 minutes max (if all good with configuration)
@marius-mihailionte339
@marius-mihailionte339 2 года назад
Hope I understood it wrong, but during KMS Decryption section you mentioned that a user use KMS CMK to generate another Plaintext DEK to decrypt cypher text data. Based on my knowledge, Encrypted DEK stored with cypher text is sent to KMS to be decrypted and then used in decryption process.
@learnwithgvr
@learnwithgvr 2 года назад
Yes you are correct... during decryption, encryption DEK will be sent to KMS to generate plain text DEK. Thanks
@jackg1067
@jackg1067 2 года назад
Thanks for the useful Video. Can I know how to use the same method for AWS EKS where we dont have access to API server and ETCD.
@learnwithgvr
@learnwithgvr 2 года назад
Good question....for such AWS EKS managed services we have to use AWS provided architectures to use AWS secret managers using IAM & secret store CSI or so( pls have a look at my video on CSI inline volumes) There is other simple way also you can acceess secrets from EKS cluster pods using IAM roles
@devathanagapuneeth7269
@devathanagapuneeth7269 2 года назад
Slack link in the description is not working. Could you provide the new link ?
@learnwithgvr
@learnwithgvr 2 года назад
Pls use new link i just updated in the description
@SaravanaKumar-km2lb
@SaravanaKumar-km2lb 2 года назад
Is there possible to integrate vault here ?? Is that recommended??
@learnwithgvr
@learnwithgvr 2 года назад
To Achieve this need Vault KMS Provider for kubernetes... I can see few i.e. by oracle & ondat github.com/oracle/kubernetes-vault-kms-plugin www.ondat.io/webinars/secure-all-your-k8s-secrets-with-a-kms-provider-plugin-and-hashicorp-vault Sorry i dont have much more information on this. However Once KMS v2 goes GA there will be many providers for sure
@SaravanaKumar-km2lb
@SaravanaKumar-km2lb 2 года назад
@@learnwithgvr thanks for your reply sir ♥️
@nithinjohn135
@nithinjohn135 2 года назад
Could you do video on external secret operator syncing with k8s
@learnwithgvr
@learnwithgvr 2 года назад
Good topic. Sure will try
@nithinjohn135
@nithinjohn135 2 года назад
@@learnwithgvraws SSM and vault also we can use for that I guess
@nithinjohn135
@nithinjohn135 2 года назад
@@learnwithgvr could you please do a video there are only few videos there for this
@melaniebaldauf7587
@melaniebaldauf7587 Год назад
promosm
Далее
These Are Too Smooth 😮‍💨
00:57
Просмотров 3,8 млн
#kikakim
00:17
Просмотров 7 млн
Ребенок по калькуляции 😂
00:32
Encrypting Secrets in Kubernetes Clusters using KMS
34:56
Securing Kubernetes Secrets (Cloud Next '19)
42:27
Просмотров 19 тыс.
Hashicorp Vault - Vault Audit Devices #11
19:09
Просмотров 1,6 тыс.
DEMO | AWS KMS | ENVELOPE ENCRYPTION
14:05
Просмотров 1,9 тыс.