Merge "Added Partial Disk (Transparent) Encryption Support via Software Encryption (LUKS) (r9, dsr8MR3)"

This commit is contained in:
Zuul 2024-04-25 14:35:45 +00:00 committed by Gerrit Code Review
commit 575af0b0e8
5 changed files with 39 additions and 1 deletions

View File

@ -0,0 +1,6 @@
.. begin-partial-disk-encrypt
.. end-partial-disk-encrypt

View File

@ -18,6 +18,10 @@ using DCManager CLI
<backup-a-subcloud-group-of-subclouds-using-dcmanager-cli-f12020a8fc42>` for
how to remotely backup a subcloud from the System Controller.
.. note::
Backup archives should be stored in a secured (offsite) location.
.. contents:: |minitoc|
:local:
:depth: 1
@ -206,7 +210,7 @@ Recommended Backup and Retention Policies
.. warning::
Using the ``-e ignore_health=true`` option should be avoided unless
it is required. Restoring an unhealthy backup will result in system issues.
it is required. Restoring an unhealthy backup will result in system issues.
- All backups are done during off-peak hours (i.e. maintenance window).

View File

@ -162,6 +162,15 @@ Encrypt Kubernetes Secret Data at Rest
encrypt-kubernetes-secret-data-at-rest
****************************************************************************
Partial Disk (Transparent) Encryption Support via Software Encryption (LUKS)
****************************************************************************
.. toctree::
:maxdepth: 1
partial-disk-transparent-encryption-support-via-software-enc-27a570f3142c
*********************
Linux Auditing System
*********************

View File

@ -0,0 +1,18 @@
.. _partial-disk-transparent-encryption-support-via-software-enc-27a570f3142c:
============================================================================
Partial Disk (Transparent) Encryption Support via Software Encryption (LUKS)
============================================================================
.. rubric:: |context|
A new encrypted filesystem using Linux Unified Key Setup (LUKS) is created
automatically on all hosts to store security-sensitive files. This is mounted
at '/var/luks/stx/luks_fs' and the files kept in '/var/luks/stx/luks_fs/controller'
directory are replicated between the controllers.
.. only:: partner
.. include:: /_includes/partial-disk-encryption-support-37cf9e2651db.rest
:start-after: begin-partial-disk-encrypt
:end-before: end-partial-disk-encrypt

View File

@ -90,6 +90,7 @@
.. |LDPC| replace:: :abbr:`LDPC (Low-Density Parity Check)`
.. |LLDP| replace:: :abbr:`LLDP (Link Layer Discovery Protocol)`
.. |LSM| replace:: :abbr:`LSM (Linux Security Modules)`
.. |LUKS| replace:: :abbr:`LUKS (Linux Unified Key Setup)`
.. |LVG| replace:: :abbr:`LVG (Local Volume Groups)`
.. |MAC| replace:: :abbr:`MAC (Media Access Control)`
.. |MEC| replace:: :abbr:`MEC (Multi-access Edge Computing)`