Encrypting Secret Data at Rest (#8574)

* change default value for Encrypting Secret Data at Rest to secretbox, remove experimental flag and add documentation

* fix MD012/no-multiple-blanks
This commit is contained in:
Alex
2022-02-23 12:04:18 +01:00
committed by GitHub
parent e053ee4272
commit 36393d77d3
3 changed files with 24 additions and 2 deletions

View File

@@ -144,7 +144,7 @@ controller_manager_extra_volumes: {}
kube_encrypt_secret_data: false
kube_encrypt_token: "{{ lookup('password', credentials_dir + '/kube_encrypt_token.creds length=32 chars=ascii_letters,digits') }}"
# Must be either: aescbc, secretbox or aesgcm
kube_encryption_algorithm: "aescbc"
kube_encryption_algorithm: "secretbox"
# Which kubernetes resources to encrypt
kube_encryption_resources: [secrets]