Makes default StorageClass to use disk encryption set, if provided #1627
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Which issue this PR addresses:
Work item №9586080.
Otherr PRs related to this work item:
What this PR does / why we need it:
This PR add a new installation step which replaces default
StorageClassprovided by OCP with a new one which uses disk encryption set (if one supplied by a customer).Test plan for issue:
PR adds unit tests + Manual tests.
For instructions on how to create a cluster with SSE and encryption at host see #1569.
How to test that default PV is encrypted.
Result must be something like this:
[ { "diskEncryptionSetId": "$DES_RESOURCE_ID", "type": "EncryptionAtRestWithCustomerKey" } ]Is there any documentation that needs to be updated for this PR?
We need to update customer facing docs and CLI, but it is out of scope of this work.