diff --git a/app-dev/devops-and-containers/oke/oke-policies/policies.md b/app-dev/devops-and-containers/oke/oke-policies/policies.md index acb3200e6..961c27d32 100644 --- a/app-dev/devops-and-containers/oke/oke-policies/policies.md +++ b/app-dev/devops-and-containers/oke/oke-policies/policies.md @@ -28,6 +28,16 @@ UNCLEAR: Maybe this policy is necessary for every IPv6 cluster Allow any-user to use ipv6s in compartment where all { request.principal.id = '' } ``` + +### ENCRYPT ETCD WITH A KEY + +To encrypt etcd secrets at rest using a custom key, this needs to be specified at cluster creation and the following policy must be in place: + +[https://docs.oracle.com/en-us/iaas/Content/ContEng/Tasks/contengencryptingdata.htm#console](https://docs.oracle.com/en-us/iaas/Content/ContEng/Tasks/contengencryptingdata.htm#console) + +``` +Allow any-user to use keys in compartment where ALL {request.principal.type = 'cluster', target.key.id = ''} +``` ### ENCRYPT BOOT VOLUME WITH KEY