-
Feature Request
-
Resolution: Done
-
Normal
-
None
-
False
-
None
-
False
-
Not Selected
-
-
-
1. Proposed title of this feature request
Tang Offline Provisioning
2. What is the nature and description of the request?
Tang supports offline provisioning by obtaining the advertisement out of band and passing it directly to Clevis. This will allow provisioning to be more stable when you have multiple Tang servers.
e.g. 5 Tang servers for availability (threshold 1). Currently, all 5 servers need to be online at provisioning time in order for Clevis to bind the LUKS device. With offline mode, we no longer need to contact the Tang servers on first boot. And for subsequent boots, unlocks will respect the threshold of 1. So at no point will the process require all 5 servers to be online.
This RFE is to enable this configuration on OCP through ignition constructs.
Please see upstream RFE: https://github.com/coreos/ignition/issues/1474
3. Why does the customer need this? (List the business requirements here)
This is required to meet security requirements for encryption of data at rest.
4. List any affected packages or components.
Tang
- depends on
-
COS-1802 [coreos/ignition] Consider supporting Tang offline provisioning
- Closed
- is related to
-
OCPSTRAT-295 Offline network-bound disk encryption provisioning
- Closed