Skip to content

ceph-csi-rbd support for integration with transit engine in vault #5697

@nics90

Description

@nics90

Describe the feature you'd like to have

What new functionality do you want?

Currently, ceph csi rbd support integration with vault/openbao key-value engine, but the integration with transit engine is also required.

What is the value to the end user? (why is it a priority?)

Openbao/Vault Key-Value engine supports creation of DEK in vault by the CSI driver but the keys cannot be rotated at all. Hence bringing Transit Engine will ease the process of key rotation which is required to be used in production use cases.

How would the end user gain value from having this feature?

Will provide more secure, standard and compliant way to integrate with vault KMS.

How will we know we have a good solution? (acceptance criteria)

Add a list of criteria that should be met for this feature to be useful

Providing integration with all the possible workflows of transit engine that vault/openbao provides.

Additional context

Add any other context or screenshots about the feature request here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions