Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Feature] Support for Disk encryption on AKS EE CBL-Maniner VM #150

Open
erwinkersten opened this issue Oct 26, 2023 · 0 comments
Open

[Feature] Support for Disk encryption on AKS EE CBL-Maniner VM #150

erwinkersten opened this issue Oct 26, 2023 · 0 comments
Assignees
Labels
enhancement New feature or request

Comments

@erwinkersten
Copy link

Feature request:

On the physical edge device, we will utilize the Bitlocker encryption feature to achieve full disk encryption. This proactive approach mitigates the risks associated with data theft or exposure resulting from lost, stolen, or improperly decommissioned devices. In addition to this, we aim to bolster security by encrypting the disks of AKS EE VMs, ensuring that they remain inaccessible when copied or transferred to another machine.

While CBL-Maniner currently supports disk encryption with a startup password, this method is not seamless, as it necessitates user intervention: and not something what you want to enable on edge devices. Is it feasible option to implement transparent disk encryption by securely binding the disk encryption keys to the virtual machine's TPM, thereby ensuring that only the AKS EE VM has exclusive access to the protected disks?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

4 participants