[openstack-dev] [nova] Encrypted Ephemeral Storage
chris.buccella at verilume.com
Mon Apr 11 17:06:39 UTC 2016
I've been looking into using encrypted ephemeral storage with LVM. With the
[ephemeral_storage_encryption] and [keymgr] sections to nova.conf, I get an
LVM volume with "-dmcrypt" is appended to the volume name, but otherwise
see no difference; I can still grep for text inside the volume.
Upon reading the source, I don't see "cryptsetup luksFormat" being called
I was expecting a new encrypted LVM volume when a new instance was created.
Are my expectations misplaced? How is this feature envisioned to work?
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the OpenStack-dev