WEBVTT - This file was automatically generated by VIMEO

0
00:00:00.100 --> 00:00:03.400
Okay. So in this video we're going to look into encrypting secret

1
00:00:03.400 --> 00:00:06.500
 data address. So if you go to the kubernetes documentation

2
00:00:06.500 --> 00:00:09.800
 pages and under tasks you have administrator cluster

3
00:00:09.800 --> 00:00:11.500
 and encrypting secret data at rest.

4
00:00:12.300 --> 00:00:13.200
You have these following.

5
00:00:14.200 --> 00:00:17.100
Documents I'm going to follow this but also kind of

6
00:00:17.100 --> 00:00:20.200
 try and explain what we're trying to do. So the first

7
00:00:20.200 --> 00:00:23.700
 thing first thing first, I'm going to start up

8
00:00:23.700 --> 00:00:24.700
 a kubernetes playground.

9
00:00:26.100 --> 00:00:28.800
So this is a single node cluster.

10
00:00:31.900 --> 00:00:32.300
right, so

11
00:00:34.600 --> 00:00:37.700
This basically uses is built with the qbarium

12
00:00:37.700 --> 00:00:41.200
 tool and has container D. I'm just going to maximize this

13
00:00:40.200 --> 00:00:43.900
 and we'll just work on the terminal. All

14
00:00:43.900 --> 00:00:46.500
 right. So the first thing's first I'm going to first create a

15
00:00:46.500 --> 00:00:48.500
 sacred object. So

16
00:00:49.700 --> 00:00:52.000
I'm going to do a cable.

17
00:00:53.400 --> 00:00:53.900
Create Secret.

18
00:00:55.700 --> 00:00:58.100
And I want a generic secrets so do that.

19
00:01:00.700 --> 00:01:02.000
and I'll probably

20
00:01:03.600 --> 00:01:07.100
create a secret from literals. I'm just going to copy this

21
00:01:06.100 --> 00:01:07.300
 command.

22
00:01:10.500 --> 00:01:13.700
Okay, I'm gonna probably P1 and super secret.

23
00:01:13.700 --> 00:01:16.600
 So that's my secret object. So my

24
00:01:16.600 --> 00:01:20.100
 secret object is created. So if I now do get secret

25
00:01:21.100 --> 00:01:23.700
I get to see my secret object and if I do it describe.

26
00:01:24.700 --> 00:01:26.100
great Secret

27
00:01:29.900 --> 00:01:32.500
you get to see that it's the the secret

28
00:01:32.500 --> 00:01:36.200
 name and the data if I want to see a little bit more do a

29
00:01:39.100 --> 00:01:43.000
Chevrolet ammo and I'm gonna do a get secret.

30
00:01:45.900 --> 00:01:48.000
Okay, and I get

31
00:01:48.200 --> 00:01:48.300
 to see.

32
00:01:49.500 --> 00:01:52.700
The data here now if you look here, so this

33
00:01:52.700 --> 00:01:55.000
 is key one and this is kind of

34
00:01:55.500 --> 00:01:58.200
 the encoded format of the secret.

35
00:01:58.200 --> 00:02:01.400
 So remember that, you know anyone could take this n decoded

36
00:02:01.400 --> 00:02:03.100
 and easily view the actual.

37
00:02:04.500 --> 00:02:06.200
Secret right. So if I do

38
00:02:07.900 --> 00:02:09.400
Let's see if I have a 64.

39
00:02:11.300 --> 00:02:12.900
Yep, I do so.

40
00:02:16.100 --> 00:02:19.200
Going to get that again. So I'm going to do a echo.

41
00:02:21.200 --> 00:02:22.300
copy and paste this

42
00:02:25.900 --> 00:02:28.100
pass it through basics for Android

43
00:02:29.600 --> 00:02:32.500
and I get to see the the secret. Okay, so so that's

44
00:02:32.500 --> 00:02:36.300
 the first thing to know that the secrets objects

45
00:02:35.300 --> 00:02:38.300
 stored in the secret configuration as

46
00:02:38.300 --> 00:02:42.200
 you see it here is just base 64 encoded.

47
00:02:41.200 --> 00:02:44.700
 So if you just do a base 64 decode you're

48
00:02:44.700 --> 00:02:48.000
 gonna see the so remember not to create your secret

49
00:02:47.300 --> 00:02:50.200
 definition files and you know, push it to GitHub or

50
00:02:50.200 --> 00:02:53.100
 something because anyone could just pick this up and run this command and

51
00:02:53.100 --> 00:02:56.000
 see the secret right? So that's the first step but I want

52
00:02:56.100 --> 00:03:00.300
 to make it clear that this the scope of this video is not really relevant to

53
00:03:00.300 --> 00:03:02.100
 this and encoding here.

54
00:03:03.300 --> 00:03:06.600
We are going to focus on the data that

55
00:03:06.600 --> 00:03:10.200
 stored within the at CD server.

56
00:03:09.200 --> 00:03:12.500
 Okay. So this after we

57
00:03:12.500 --> 00:03:15.200
 are done this part is still going to be still going

58
00:03:15.200 --> 00:03:18.500
 to remain the same. So we're not really focusing on this part right

59
00:03:18.500 --> 00:03:21.800
 here. What we're focusing on is how

60
00:03:21.800 --> 00:03:24.600
 the data is stored in the hcd server.

61
00:03:24.600 --> 00:03:25.300
 So that's the focus.

62
00:03:27.300 --> 00:03:30.700
So let's first look at how this data is stored in the hcd

63
00:03:30.700 --> 00:03:30.900
 server.

64
00:03:31.900 --> 00:03:34.600
Okay, so for that if you go to the

65
00:03:34.600 --> 00:03:37.200
 bottom of this there is this command

66
00:03:37.200 --> 00:03:40.300
 and it's uses the HD color API version

67
00:03:40.300 --> 00:03:43.400
 3. It runs the city cuddle command passing the

68
00:03:43.400 --> 00:03:47.000
 Cs certificates for authentication and we're going to get this particular

69
00:03:46.500 --> 00:03:47.700
 secret. So

70
00:03:48.700 --> 00:03:51.500
The way that is stored in its a day is stored in

71
00:03:51.500 --> 00:03:55.400
 registry and secrets and default and this is the secret name. So let

72
00:03:54.400 --> 00:03:57.400
 me first see if we have the HD cuddle

73
00:03:57.400 --> 00:04:00.000
 command line so we don't have that. So the first

74
00:04:00.100 --> 00:04:03.400
 step is to get that installed. So I'm just going to do it if you

75
00:04:03.400 --> 00:04:03.900
 can install.

76
00:04:05.700 --> 00:04:07.300
I think it's it's CD find.

77
00:04:12.800 --> 00:04:15.300
Yeah, so if you do not have the hcd.

78
00:04:16.600 --> 00:04:19.100
On so so remember that the Etsy

79
00:04:19.100 --> 00:04:22.300
 server is running in a pod so you can either SSH into

80
00:04:22.300 --> 00:04:25.200
 the exact into the pot and then runs it CD cuddle

81
00:04:25.200 --> 00:04:28.500
 command from within that or if you're you want to write locally from

82
00:04:28.500 --> 00:04:31.400
 your control plane node, you could use the LCD cuddle

83
00:04:31.400 --> 00:04:34.500
 client. Usually now if the client command line

84
00:04:34.500 --> 00:04:37.300
 utility is not available you have different options

85
00:04:37.300 --> 00:04:41.000
 to install it on different systems. So,

86
00:04:40.800 --> 00:04:41.800
 let's see.

87
00:04:45.300 --> 00:04:48.700
Okay, so I have it installed on my machine using the

88
00:04:48.700 --> 00:04:51.600
 HD the package STD

89
00:04:51.600 --> 00:04:54.600
 client. So look up for whatever it

90
00:04:54.600 --> 00:04:57.200
 is that your the version

91
00:04:57.200 --> 00:04:58.200
 of that City that you're running.

92
00:04:59.200 --> 00:05:02.100
Okay, so that's there. So now we've got it City cuddle utility. So that's

93
00:05:02.100 --> 00:05:05.200
 remember that's the client only the server still running on.

94
00:05:06.700 --> 00:05:09.500
As a part, so if you'll get thoughts -

95
00:05:09.500 --> 00:05:11.000
 Cube system.

96
00:05:14.800 --> 00:05:15.600
I have

97
00:05:16.700 --> 00:05:18.200
The STD control plane here, right?

98
00:05:19.500 --> 00:05:22.300
Okay, so the next step is to run this

99
00:05:22.300 --> 00:05:25.600
 so first remember that you need the the

100
00:05:25.600 --> 00:05:27.300
 certificate file. So, let's see if we have that.

101
00:05:29.400 --> 00:05:32.200
Yeah, we do. So under the under hcd you have all the

102
00:05:32.200 --> 00:05:36.000
 certificates files needed for it for connecting or authenticating

103
00:05:35.100 --> 00:05:38.300
 to the city server. So that's good. So I'm gonna

104
00:05:38.300 --> 00:05:41.400
 copy this command remember to set the version at

105
00:05:41.400 --> 00:05:44.700
 City cuddle API version to 3 and the name

106
00:05:44.700 --> 00:05:46.400
 of the secret is secret one.

107
00:05:47.400 --> 00:05:48.900
See what I created.

108
00:05:49.900 --> 00:05:50.900
It's secrets.

109
00:05:51.600 --> 00:05:54.300
So it's named my secrets. I'm gonna replace that with my

110
00:05:54.300 --> 00:05:57.900
 secret. We'll do my secret. If I

111
00:05:57.900 --> 00:06:00.300
 just run this command, you can see that it kind of gives me

112
00:06:00.300 --> 00:06:03.400
 a kind of a jumbled information, but you

113
00:06:03.400 --> 00:06:06.500
 can kind of see the secret there as is

114
00:06:06.500 --> 00:06:09.300
 right. You can see the secret there in the

115
00:06:09.300 --> 00:06:12.500
 text format to see it in this format. You just

116
00:06:12.500 --> 00:06:13.300
 need to append.

117
00:06:13.900 --> 00:06:15.000
The hex dumped to it.

118
00:06:16.300 --> 00:06:17.600
Because sometimes you may not be able to see it.

119
00:06:18.500 --> 00:06:21.400
In the right format. So this is the data that's stored in a CD

120
00:06:21.400 --> 00:06:24.700
 and if you look closely you'll see that the the secret

121
00:06:24.700 --> 00:06:27.300
 that I have the password or whatever it is that I've stored

122
00:06:27.300 --> 00:06:30.700
 is actually visible like this. So the data

123
00:06:30.700 --> 00:06:33.400
 is stored in a CD in

124
00:06:33.400 --> 00:06:36.200
 a an unencrypted format. So anyone with access to

125
00:06:36.200 --> 00:06:40.300
 hcd will be able to just go through and get all the secret secrets

126
00:06:39.300 --> 00:06:42.700
 and other confidential information stored as a

127
00:06:42.700 --> 00:06:43.000
 secret object.

128
00:06:44.200 --> 00:06:47.600
So that's that's the problem here. So this is the problem that we are trying to solve by

129
00:06:47.600 --> 00:06:50.900
 enabling encryption at rest in NCD.

130
00:06:51.400 --> 00:06:53.100
now if you go through this document

131
00:06:54.200 --> 00:06:57.200
first thing that it says is first we

132
00:06:57.200 --> 00:07:00.200
 need to determine if encryption address is already enabled or

133
00:07:00.200 --> 00:07:03.800
 not. So this is done with the property called encryption provider

134
00:07:03.800 --> 00:07:05.000
 config. So if I go to

135
00:07:06.400 --> 00:07:10.000
Thank you, very server. So let's say my QPS service running as

136
00:07:09.200 --> 00:07:11.400
 a process here.

137
00:07:12.300 --> 00:07:16.300
And let me just grab for cube API server

138
00:07:16.300 --> 00:07:18.100
 and I get to see the queen APS server.

139
00:07:19.800 --> 00:07:22.700
Process running with all the options. Let's first

140
00:07:22.700 --> 00:07:24.400
 see if it has the encryption provider.

141
00:07:25.100 --> 00:07:27.200
Config option. So that's the first thing that we'll do.

142
00:07:30.400 --> 00:07:33.100
This is to check if I can encryption at rest is already

143
00:07:33.100 --> 00:07:36.100
 enabled and as you can see it does not return a result. So that

144
00:07:36.100 --> 00:07:39.500
 means this option is not configured you can we can also kind of

145
00:07:39.500 --> 00:07:42.300
 verify this because this is a cube ADM setup.

146
00:07:42.300 --> 00:07:43.800
 It uses the

147
00:07:46.900 --> 00:07:47.400
War

148
00:07:50.700 --> 00:07:51.600
manifest

149
00:07:53.800 --> 00:07:54.700
Okay, see.

150
00:07:56.700 --> 00:07:59.700
Kubernetes manifest yeah, it is a kubernetes

151
00:07:59.700 --> 00:08:02.200
 manifest and here you have the cube APS

152
00:08:02.200 --> 00:08:05.000
 server. So if configuration, so if you look at

153
00:08:07.700 --> 00:08:08.800
this particular file

154
00:08:10.700 --> 00:08:11.600
into a cat

155
00:08:12.500 --> 00:08:15.100
we'll be able to see all the options provided and here you don't

156
00:08:15.100 --> 00:08:15.600
 see the

157
00:08:16.800 --> 00:08:18.300
encryption option

158
00:08:19.300 --> 00:08:22.200
that we have talked about here. So this means that encryption address is

159
00:08:22.200 --> 00:08:25.400
 not not enabled. So that's the first step and we've already verified that

160
00:08:25.400 --> 00:08:28.800
 by creating the secret subject. Okay.

161
00:08:28.800 --> 00:08:32.900
 So the next step is to create a configuration

162
00:08:32.900 --> 00:08:35.500
 file and then pass it in as this particular

163
00:08:35.500 --> 00:08:38.500
 option. So that's it. So that's basically the steps required to

164
00:08:38.500 --> 00:08:41.200
 enable encryption press you create a configuration file and

165
00:08:41.200 --> 00:08:42.300
 you pass it in as an option.

166
00:08:43.500 --> 00:08:46.200
So let's look at the configuration file. So this is what it is. So you have

167
00:08:46.200 --> 00:08:49.200
 the APA version you have the kind is encryption configuration. And

168
00:08:49.200 --> 00:08:52.200
 then you have resources now you can pick and choose

169
00:08:52.200 --> 00:08:56.000
 which resources you want to encrypt right? So

170
00:08:55.500 --> 00:08:58.300
 you have pause deployments and secrets and

171
00:08:58.300 --> 00:09:01.400
 services. You want to store all

172
00:09:01.400 --> 00:09:04.500
 of them as encrypted. You might not because not everything

173
00:09:04.500 --> 00:09:07.100
 is confidential right? So you need not

174
00:09:07.100 --> 00:09:10.500
 necessarily encrypt and save all the data about parts

175
00:09:10.500 --> 00:09:13.500
 and and deployment here are concern

176
00:09:13.500 --> 00:09:16.300
 is just secret so under resources you specify the

177
00:09:16.300 --> 00:09:19.800
 target. So this is secrets. That means only the secret objects are going

178
00:09:19.800 --> 00:09:22.400
 to be encrypted. Now, you can

179
00:09:22.400 --> 00:09:25.200
 encrypt something using a set

180
00:09:25.200 --> 00:09:28.400
 of providers, right? So the default one is called identity and

181
00:09:28.400 --> 00:09:31.300
 the identity provider just means that there's no

182
00:09:31.300 --> 00:09:34.600
 encryption at all. So you can see the list of providers here and it

183
00:09:34.600 --> 00:09:37.900
 says the identity to provide to say, there's no encryption resources are

184
00:09:37.900 --> 00:09:39.600
 rich and essays without any encryption.

185
00:09:40.400 --> 00:09:43.200
So and then you have other providers which are

186
00:09:43.200 --> 00:09:46.800
 these and those are listed here. So you have the secret box you have

187
00:09:46.800 --> 00:09:49.800
 the AES GCM the as

188
00:09:49.800 --> 00:09:52.700
 CBC so CBC, so all of these are encryption algorithms

189
00:09:52.700 --> 00:09:55.400
 different encryption algorithms and you can see the details

190
00:09:55.400 --> 00:09:56.000
 about how they are.

191
00:09:57.100 --> 00:09:58.100
how they encrypt here

192
00:09:59.300 --> 00:10:02.700
so you can choose whichever one you want and provide

193
00:10:02.700 --> 00:10:05.400
 a key. So this key has a

194
00:10:05.400 --> 00:10:08.800
 secret you can provide multiple keys keys and

195
00:10:08.800 --> 00:10:11.000
 secrets and this secret is what will be

196
00:10:11.200 --> 00:10:14.500
 used to use for the encryption by the encryption algorithm

197
00:10:14.500 --> 00:10:15.800
 right now.

198
00:10:16.700 --> 00:10:19.200
One thing to note here is the order. So this as you

199
00:10:19.200 --> 00:10:22.400
 can see providers is a list. So these this is the first item in

200
00:10:22.400 --> 00:10:25.200
 the list second item in the list third item and the reason for the

201
00:10:25.200 --> 00:10:28.200
 item in the list. So this order matters because when

202
00:10:29.800 --> 00:10:32.900
When the encryption happens it first,

203
00:10:32.900 --> 00:10:35.300
 it uses this to encrypt and then

204
00:10:35.300 --> 00:10:38.700
 it could use any of these to decrypt right? So

205
00:10:38.700 --> 00:10:41.400
 always encryption happens with

206
00:10:41.400 --> 00:10:44.900
 this. So if identity provider, which is a pro,

207
00:10:44.900 --> 00:10:47.200
 which has no encryption is the first one

208
00:10:47.200 --> 00:10:50.300
 then there's no encryption enable at all.

209
00:10:50.300 --> 00:10:53.100
 So that's how that's how it works. So if this is the first

210
00:10:53.100 --> 00:10:56.700
 one that means this is what is you going to be used for encryption and

211
00:10:56.700 --> 00:11:00.100
 since it's identity it's not going to encrypt anything

212
00:10:59.100 --> 00:11:02.200
 at all. So if we if you really want

213
00:11:02.200 --> 00:11:02.800
 to encrypt

214
00:11:04.600 --> 00:11:07.300
The data and SED then one of these should be

215
00:11:07.300 --> 00:11:10.700
 at the top. Okay, so that's that's then that's

216
00:11:10.700 --> 00:11:13.100
 the whatever is the first one is what's going to be used for

217
00:11:13.100 --> 00:11:13.700
 encryption.

218
00:11:14.400 --> 00:11:17.700
So let's just do this real quick. So we're

219
00:11:17.700 --> 00:11:20.100
 going to create a very simple version of this

220
00:11:20.100 --> 00:11:20.900
 file, which is

221
00:11:21.700 --> 00:11:24.400
Which is this and this as you can see, we have specified that

222
00:11:24.400 --> 00:11:27.900
 all the secrets are going to be encrypted and we're going to use the AES

223
00:11:27.900 --> 00:11:30.300
 CBC encryption provider

224
00:11:30.300 --> 00:11:33.200
 and you as you can see identities at the bottom. So the first one

225
00:11:33.200 --> 00:11:36.500
 is a CVC. So this is what is going to be used for encryption. Now

226
00:11:36.500 --> 00:11:37.500
 this requires a secret.

227
00:11:38.300 --> 00:11:41.200
Object so we could generate a 32 by random key using this

228
00:11:41.200 --> 00:11:42.600
 using this. I'm just gonna

229
00:11:43.300 --> 00:11:43.900
copy this

230
00:11:46.600 --> 00:11:49.300
and get that key first. So this that's what our key

231
00:11:49.300 --> 00:11:53.500
 is going to be. Then I'm going to copy this and create encryption

232
00:11:52.500 --> 00:11:55.400
 object file. So I'll

233
00:11:55.400 --> 00:11:57.100
 call it PNC dot ammo.

234
00:11:59.200 --> 00:12:00.700
And I'm going to paste this.

235
00:12:03.800 --> 00:12:06.800
Okay should have copied the secret.

236
00:12:08.300 --> 00:12:09.900
Value first I'm going to copy this.

237
00:12:12.800 --> 00:12:15.300
And I'm going to go here and replace.

238
00:12:16.200 --> 00:12:17.200
the secret object here

239
00:12:21.300 --> 00:12:21.600
Okay.

240
00:12:23.400 --> 00:12:28.000
Okay, so that's that. So now I have the encryption configuration

241
00:12:27.400 --> 00:12:30.500
 file. It's currently in my

242
00:12:30.500 --> 00:12:32.800
 home directory now. All I need to do is

243
00:12:33.800 --> 00:12:34.400
go and

244
00:12:35.400 --> 00:12:38.300
edit this file. So that's the next step shown

245
00:12:38.300 --> 00:12:39.300
 here. So.

246
00:12:40.500 --> 00:12:44.100
In the cube API server. I'm going to add this line to point

247
00:12:43.100 --> 00:12:46.500
 to the encryption file that is just created then

248
00:12:46.500 --> 00:12:49.100
 of course we need to since the file

249
00:12:49.100 --> 00:12:52.500
 is created locally. I have to mount it inside. So I'm going to use volumes and

250
00:12:52.500 --> 00:12:55.400
 volume mounts. If you have not gone through the volumes

251
00:12:55.400 --> 00:12:59.000
 and volume months yet. Then you might want to take a

252
00:12:58.300 --> 00:13:01.200
 look at that and come back but this is

253
00:13:01.200 --> 00:13:05.000
 pretty straightforward. So here you have the directory

254
00:13:04.200 --> 00:13:07.800
 the local directory and that's on my

255
00:13:07.800 --> 00:13:10.500
 on my mission on my control panel node here

256
00:13:10.500 --> 00:13:13.700
 and this directory is going to be mapped to this path

257
00:13:13.700 --> 00:13:16.700
 within the Pod and then so anything

258
00:13:16.700 --> 00:13:19.200
 that's available here is going to be available here. That's it.

259
00:13:19.200 --> 00:13:22.400
 So first I'm gonna

260
00:13:22.400 --> 00:13:25.400
 create this local directory so they can put my

261
00:13:25.400 --> 00:13:26.100
 file there.

262
00:13:27.300 --> 00:13:30.200
And move my encryption file from

263
00:13:30.200 --> 00:13:30.500
 here.

264
00:13:31.500 --> 00:13:33.500
to local directory

265
00:13:34.700 --> 00:13:35.000
make sure

266
00:13:36.600 --> 00:13:38.700
yep, so I have the file there now.

267
00:13:39.500 --> 00:13:42.100
So now I'm going to edit the cube API server manifest file and then

268
00:13:42.100 --> 00:13:45.100
 make this changes. Okay, so that's next step. So

269
00:13:45.100 --> 00:13:45.700
 I'm gonna go into

270
00:13:47.300 --> 00:13:47.300
It is.

271
00:13:49.100 --> 00:13:51.000
manifest and Cube API server

272
00:13:53.300 --> 00:13:55.300
and the first thing that I'm going to do

273
00:13:56.400 --> 00:13:58.600
I'm going to add.

274
00:14:01.600 --> 00:14:02.500
this line

275
00:14:04.100 --> 00:14:04.400
so this

276
00:14:05.500 --> 00:14:08.600
Is what tells where the encryption configuration file

277
00:14:08.600 --> 00:14:11.200
 is? So that's the first step and I'm going to go down.

278
00:14:13.300 --> 00:14:16.800
So I have two things I have volume mounts. So this is inside

279
00:14:16.800 --> 00:14:19.400
 my volume inside the

280
00:14:19.400 --> 00:14:19.600
 pod.

281
00:14:20.200 --> 00:14:23.500
Where is going to be mounted so I'm going to copy this.

282
00:14:26.300 --> 00:14:29.800
So the directory the local directory is going

283
00:14:29.800 --> 00:14:32.200
 to be mounted into this path. So that's the first

284
00:14:32.200 --> 00:14:35.000
 step then below under mount. I'm going to

285
00:14:37.500 --> 00:14:38.400
specify

286
00:14:40.500 --> 00:14:42.100
the location of my local directory

287
00:14:45.300 --> 00:14:48.200
Okay. So this is how it works on my

288
00:14:48.200 --> 00:14:51.700
 local host the Etsy kubernetes. ENC directory is

289
00:14:51.700 --> 00:14:52.500
 going to be mapped.

290
00:14:53.800 --> 00:14:54.100
to

291
00:14:57.700 --> 00:15:00.900
the HTC kubernetes Inc directory

292
00:15:00.900 --> 00:15:01.600
 inside the pod

293
00:15:02.300 --> 00:15:02.700
and then

294
00:15:04.700 --> 00:15:07.200
so since my enc.aml file is available

295
00:15:07.200 --> 00:15:10.400
 locally that file is going to be available inside and that's it.

296
00:15:10.400 --> 00:15:11.900
 Okay, save that.

297
00:15:13.100 --> 00:15:16.400
So now that I've saved image changes to this file the QB

298
00:15:16.400 --> 00:15:19.500
 APS ever should be restarting. So let's just give it

299
00:15:19.500 --> 00:15:22.100
 a few seconds. Let's see. Okay, so this is

300
00:15:22.100 --> 00:15:22.400
 now

301
00:15:23.500 --> 00:15:24.900
It's now gone, so I'm going to wait.

302
00:15:26.800 --> 00:15:27.600
For it to come back.

303
00:15:29.900 --> 00:15:32.100
waiting and if you want to see the

304
00:15:32.100 --> 00:15:35.200
 status of the qbps server since we're using

305
00:15:37.600 --> 00:15:39.800
container so you could use a try cuddle command.

306
00:15:40.700 --> 00:15:42.300
You could do the Cricut pause to see.

307
00:15:43.100 --> 00:15:46.100
Just come up. Okay, so it looks like it's ready three seconds ago.

308
00:15:47.300 --> 00:15:49.200
I'm just gonna do. Yep, so it's back.

309
00:15:50.700 --> 00:15:53.200
Okay, so now let's do

310
00:15:53.200 --> 00:15:57.300
 a psax and grab for you. Yes

311
00:15:56.300 --> 00:15:57.600
 server.

312
00:15:58.200 --> 00:16:01.200
And let's see if it has just to confirm if

313
00:16:01.200 --> 00:16:02.400
 it has the encryption.

314
00:16:04.600 --> 00:16:07.700
Yeah, so it looks like it has the encryption provider configured. Okay,

315
00:16:07.700 --> 00:16:10.900
 so that's that's good. Now what

316
00:16:10.900 --> 00:16:11.700
 we're going to do is

317
00:16:12.800 --> 00:16:13.900
going to create another.

318
00:16:15.800 --> 00:16:15.900
Secrets file

319
00:16:19.200 --> 00:16:22.400
So we're going to create a secret object. So we're going to create

320
00:16:22.400 --> 00:16:23.900
 cute color create Secret.

321
00:16:25.300 --> 00:16:25.600
in Eric

322
00:16:33.300 --> 00:16:35.000
okay, and we are going to

323
00:16:36.800 --> 00:16:38.400
say pick this

324
00:16:45.500 --> 00:16:48.200
and this time we'll just create the second one, which is key to

325
00:16:50.700 --> 00:16:54.100
To have key to and it's called the values

326
00:16:53.100 --> 00:16:54.500
 top secret.

327
00:16:55.500 --> 00:16:56.100
We create that.

328
00:16:57.800 --> 00:17:00.500
My secret already exists. I'm gonna say my secret

329
00:17:00.500 --> 00:17:00.900
 to

330
00:17:02.200 --> 00:17:03.100
maybe yep.

331
00:17:04.600 --> 00:17:07.700
Okay, so I now have two there's the

332
00:17:07.700 --> 00:17:10.800
 first one I created. This is the second one. I just created after encryption was

333
00:17:10.800 --> 00:17:13.600
 enabled. So I'm going to go and run the

334
00:17:14.400 --> 00:17:17.100
same command as I did previously to check

335
00:17:17.100 --> 00:17:17.700
 the status of

336
00:17:22.100 --> 00:17:23.700
that within a city so

337
00:17:24.700 --> 00:17:25.500
this

338
00:17:26.400 --> 00:17:29.500
and the name is my favorite, too.

339
00:17:30.900 --> 00:17:31.100
and

340
00:17:35.500 --> 00:17:39.100
Okay, and as you can see I can

341
00:17:38.100 --> 00:17:39.900
 no longer see.

342
00:17:41.200 --> 00:17:44.200
The top secrets of the value of top secret and I don't I no longer see

343
00:17:44.200 --> 00:17:46.600
 that here. That means encryption is enabled.

344
00:17:47.900 --> 00:17:50.600
Okay, and if I do the same

345
00:17:50.600 --> 00:17:51.500
 for the old one?

346
00:17:52.300 --> 00:17:54.700
I still see the super secret now. This is because

347
00:17:55.700 --> 00:17:58.300
After encryption is enabled only things that

348
00:17:58.300 --> 00:18:00.400
 you create newly will be.

349
00:18:02.200 --> 00:18:05.500
Will be encrypted everything that exists previously won't be

350
00:18:05.500 --> 00:18:08.700
 re-encrypted. But if you update an

351
00:18:08.700 --> 00:18:11.900
 existing configuration, then that will be re-encrypted. So

352
00:18:11.900 --> 00:18:14.600
 one of the things that you have here is to ensure all

353
00:18:14.600 --> 00:18:17.500
 secrets are encrypted. So to and what

354
00:18:17.500 --> 00:18:20.400
 this is doing is basically you're getting getting the secrets and then just re

355
00:18:20.400 --> 00:18:24.500
 replacing them with the same Json file. So

356
00:18:23.500 --> 00:18:27.600
 essentially you're just updating and

357
00:18:26.600 --> 00:18:28.700
 the objects with the same data.

358
00:18:29.700 --> 00:18:32.400
So I'm just gonna do that. So that's done. And if

359
00:18:32.400 --> 00:18:35.300
 I run the same command again, I see that it's no longer sees the

360
00:18:35.300 --> 00:18:36.200
 super super secret.

361
00:18:37.100 --> 00:18:40.500
All right, so that's basically encrypting secret data

362
00:18:40.500 --> 00:18:40.900
 at rest.

363
00:18:42.600 --> 00:18:45.300
Using one of these encryption algorithms right? Thank you

364
00:18:45.300 --> 00:18:47.300
 very much, and I'll see you in the next one.
