Skip to content

Commit 1ae9cb2

Browse files
author
immutablet
committed
Remove encryption via locally stored key.
1 parent b6860f7 commit 1ae9cb2

File tree

2 files changed

+0
-20
lines changed

2 files changed

+0
-20
lines changed

cluster/gce/config-default.sh

Lines changed: 0 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -218,25 +218,6 @@ if [[ ${ENABLE_METADATA_CONCEALMENT:-} == "true" ]]; then
218218
PROVIDER_VARS="${PROVIDER_VARS:-} ENABLE_METADATA_CONCEALMENT METADATA_CONCEALMENT_NO_FIREWALL"
219219
fi
220220

221-
222-
# Enable AESGCM encryption of secrets by default.
223-
ENCRYPTION_PROVIDER_CONFIG="${ENCRYPTION_PROVIDER_CONFIG:-}"
224-
if [[ -z "${ENCRYPTION_PROVIDER_CONFIG}" ]]; then
225-
ENCRYPTION_PROVIDER_CONFIG=$(cat << EOM | base64 | tr -d '\r\n'
226-
kind: EncryptionConfiguration
227-
apiVersion: apiserver.config.k8s.io/v1
228-
resources:
229-
- resources:
230-
- secrets
231-
providers:
232-
- aesgcm:
233-
keys:
234-
- name: key1
235-
secret: $(dd if=/dev/urandom iflag=fullblock bs=32 count=1 2>/dev/null | base64 | tr -d '\r\n')
236-
EOM
237-
)
238-
fi
239-
240221
# Optional: Enable node logging.
241222
ENABLE_NODE_LOGGING="${KUBE_ENABLE_NODE_LOGGING:-true}"
242223
LOGGING_DESTINATION="${KUBE_LOGGING_DESTINATION:-gcp}" # options: elasticsearch, gcp

cluster/gce/util.sh

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1283,7 +1283,6 @@ ETCD_CA_KEY: $(yaml-quote ${ETCD_CA_KEY_BASE64:-})
12831283
ETCD_CA_CERT: $(yaml-quote ${ETCD_CA_CERT_BASE64:-})
12841284
ETCD_PEER_KEY: $(yaml-quote ${ETCD_PEER_KEY_BASE64:-})
12851285
ETCD_PEER_CERT: $(yaml-quote ${ETCD_PEER_CERT_BASE64:-})
1286-
ENCRYPTION_PROVIDER_CONFIG: $(yaml-quote ${ENCRYPTION_PROVIDER_CONFIG:-})
12871286
SERVICEACCOUNT_ISSUER: $(yaml-quote ${SERVICEACCOUNT_ISSUER:-})
12881287
EOF
12891288
# KUBE_APISERVER_REQUEST_TIMEOUT_SEC (if set) controls the --request-timeout

0 commit comments

Comments
 (0)