Repository navigation
docs(operations): add encryption at rest guides for etcd and Keycloak - #742
Open
Andrei Kvapil (kvaps) wants to merge 3 commits into
Open
Andrei Kvapil (kvaps) wants to merge 3 commits into
Andrei Kvapil (kvaps) wants to merge 3 commits into
Conversation
Add an Encryption at Rest section that explains what Cozystack stores where and how it is protected by default, and a guide to encrypt the management cluster etcd with KMS v2 and HashiCorp Vault Transit on Talos v1.14. The guide also encrypts Flux HelmReleases, which carry application values, explains what applies to aggregated API servers, and shows the local-key option for tenant Kubernetes clusters, where KMS is not supported yet. Assisted-by: LLM Signed-off-by: Andrei Kvapil <kvapss@gmail.com>
Describe how to enable keycloak-kms-proxy on the platform Keycloak with HashiCorp Vault Transit: Vault setup, creating the shared DEK set, encrypting existing rows in a maintenance window, enabling the proxy through the cozystack.keycloak package, verification and limits. The guide makes deksetSecretName mandatory: without it the proxy mints a new key on every start and cannot read data written before a restart. Assisted-by: LLM Signed-off-by: Andrei Kvapil <kvapss@gmail.com>
✅ Deploy Preview for cozystack ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
Contributor
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configuration
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
1 of 12 tasks
The keycloak chart now refuses to enable encryption without encryption.deksetSecretName, so describe that instead of a default to avoid. Assisted-by: LLM Signed-off-by: Andrei Kvapil <kvapss@gmail.com>
Andrei Kvapil (kvaps)
marked this pull request as ready for review
October 8, 2026 16:17
Andrei Kvapil (kvaps)
requested review from
Timofei Larkin (lllamnyp),
myasnikovdaniil and
Timur Tukaev (tym83)
as code owners
October 8, 2026 16:17
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Do not merge until cozystack/cozystack#4818 is merged. The Keycloak page describes the chart behaviour from that PR: encryption is refused without a DEK set, and the static KEK is generated in a form the proxy accepts.
New section under Operations: Encryption at Rest. It goes to
next/only, because the etcd part needs Talos v1.14, which ships with the upcoming release.Three pages:
vault-kubernetes-kmsrunning as a Talos static pod. It also encrypts Flux HelmReleases, because application values (passwords included) live inspec.values. Short notes for aggregated API servers (the Cozystack API has no storage of its own, so it is already covered) and for tenant clusters, where KMS is not possible yet and the page shows the local-key option through the existingcontrolPlane.apiServervalues.The Keycloak page makes
deksetSecretNamemandatory. With the current chart default (empty) the proxy mints a new DEK on every start and keeps it only in memory, so after a proxy restart it cannot decrypt anything it wrote before (cmd/proxy/main.go,buildCipher). The fix is cozystack/cozystack#4818, which also makes the default static backend start at all.How this was checked:
kubernetesandkeycloakcharts on main.helm templateon main.Not run end to end on a clean cluster: the Talm node-file flow with
$patch: deleteforsecretboxEncryptionSecret, and the local-key option for tenant clusters.