Makes default StorageClass to use disk encryption set, if provided#1627
Merged
mjudeikis merged 1 commit intoAzure:masterfrom Aug 3, 2021
Merged
Makes default StorageClass to use disk encryption set, if provided#1627mjudeikis merged 1 commit intoAzure:masterfrom
mjudeikis merged 1 commit intoAzure:masterfrom
Conversation
6c29692 to
e2daa4e
Compare
Contributor
|
CI failures related to Azure/azure-cli#18950 it seems. |
m1kola
commented
Jul 22, 2021
bb1699d to
f6dfa46
Compare
Makdaam
previously approved these changes
Jul 28, 2021
Contributor
Makdaam
left a comment
There was a problem hiding this comment.
/lgtm
My only hangup was DiskEncryptionSetID validataion. But that's already covered in static validation of the pattern. It's a reasonable place to stop as any live check to see if the DiskEncryptionSet is usable suffers from time of check/time of use issues.
f6dfa46 to
910a72a
Compare
Contributor
Author
|
Rebased on top of the master to fix python tests. |
mjudeikis
approved these changes
Jul 28, 2021
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Which issue this PR addresses:
Work item №9586080.
Otherr PRs related to this work item:
What this PR does / why we need it:
This PR add a new installation step which replaces default
StorageClassprovided by OCP with a new one which uses disk encryption set (if one supplied by a customer).Test plan for issue:
PR adds unit tests + Manual tests.
For instructions on how to create a cluster with SSE and encryption at host see #1569.
How to test that default PV is encrypted.
Result must be something like this:
[ { "diskEncryptionSetId": "$DES_RESOURCE_ID", "type": "EncryptionAtRestWithCustomerKey" } ]Is there any documentation that needs to be updated for this PR?
We need to update customer facing docs and CLI, but it is out of scope of this work.