<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Encryption at Rest on Cozystack</title><link>https://deploy-preview-742--cozystack.netlify.app/docs/next/operations/encryption/</link><description>Recent content in Encryption at Rest on Cozystack</description><generator>Hugo</generator><language>en</language><atom:link href="https://deploy-preview-742--cozystack.netlify.app/docs/next/operations/encryption/index.xml" rel="self" type="application/rss+xml"/><item><title>Encrypting etcd with KMS v2</title><link>https://deploy-preview-742--cozystack.netlify.app/docs/next/operations/encryption/etcd-kms/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://deploy-preview-742--cozystack.netlify.app/docs/next/operations/encryption/etcd-kms/</guid><description>&lt;p&gt;This guide moves the encryption key of the management cluster etcd out of the cluster. kube-apiserver encrypts each object with a data encryption key (DEK), and the DEK is encrypted by a key encryption key (KEK) that stays in 
&lt;a href="https://developer.hashicorp.com/vault/docs/secrets/transit" target="_blank"&gt;HashiCorp Vault&lt;/a&gt; Transit. 
&lt;a href="https://github.com/FalcoSuessgott/vault-kubernetes-kms" target="_blank"&gt;vault-kubernetes-kms&lt;/a&gt; is the 
&lt;a href="https://kubernetes.io/docs/tasks/administer-cluster/kms-provider/" target="_blank"&gt;KMS v2&lt;/a&gt; plugin that connects kube-apiserver to Vault.&lt;/p&gt;
&lt;p&gt;After you finish, an etcd snapshot or a stolen disk no longer exposes Secrets or application values: decrypting them requires a call to Vault from one of the control-plane nodes. See 
&lt;a href="https://deploy-preview-742--cozystack.netlify.app/docs/next/operations/encryption/"&gt;Encryption at Rest&lt;/a&gt; for what is stored where.&lt;/p&gt;</description></item><item><title>Encrypting Keycloak User Data</title><link>https://deploy-preview-742--cozystack.netlify.app/docs/next/operations/encryption/keycloak/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://deploy-preview-742--cozystack.netlify.app/docs/next/operations/encryption/keycloak/</guid><description>&lt;p&gt;The platform Keycloak keeps its users in PostgreSQL in plain text: anyone with access to the database, a dump or a backup can read every username, email and name. 
&lt;a href="https://github.com/cozystack/keycloak-kms-proxy" target="_blank"&gt;keycloak-kms-proxy&lt;/a&gt; sits between Keycloak and PostgreSQL and encrypts these columns on the way in and decrypts them on the way out, so the database holds only ciphertext.&lt;/p&gt;
&lt;p&gt;The proxy encrypts the columns with data encryption keys (DEKs). The DEKs are stored wrapped by a key in 
&lt;a href="https://developer.hashicorp.com/vault/docs/secrets/transit" target="_blank"&gt;HashiCorp Vault&lt;/a&gt; Transit and are unwrapped in memory when the proxy starts.&lt;/p&gt;</description></item></channel></rss>