VMware vSphere CSI 2.0 – with native Kubernetes to encrypt individual Persistent Volumes on vSAN

VMware vSphere CSI 2.0 – to create a Storage Policy Based Management (SPBM) with the VM Encryption feature which can be used with vSphere CSI/CNS to create a Kubernetes Storage Class that encrypts Persistent Volumes. This feature is only available with the CSI 2.0 driver for native, upstream Kubernetes deployed on vSphere 7.0 (at the time of writing). You will also need to have a Key Management Server available to the vSphere host to create a policy that allows encryption. Finally, encrypted Persistent Volumes can only be attached to encrypted virtual machines, meaning that at least one of your Kubernetes worker nodes, deployed as a VM on vSphere, will need to be encrypted

Leave a Reply

You must be logged in to post a comment.