<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Storage on Daniel Ops</title><link>https://danielchg.github.io/tags/storage/</link><description>Recent content in Storage on Daniel Ops</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 06 Oct 2026 09:00:00 +0200</lastBuildDate><atom:link href="https://danielchg.github.io/tags/storage/index.xml" rel="self" type="application/rss+xml"/><item><title>ODF Storage Encryption using HashiCorp Vault as KMS</title><link>https://danielchg.github.io/posts/odf-encryption-vault/</link><pubDate>Tue, 06 Oct 2026 09:00:00 +0200</pubDate><guid>https://danielchg.github.io/posts/odf-encryption-vault/</guid><description>&lt;h1 id="table-of-contents"&gt;Table of Contents&lt;/h1&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;a href="#table-of-contents"&gt;Table of Contents&lt;/a&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;a href="#introduction"&gt;Introduction&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#architecture-overview"&gt;Architecture Overview&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#install-and-configure-vault-in-the-hub-cluster"&gt;Install and Configure Vault in the HUB Cluster&lt;/a&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;a href="#install-vault-with-helm"&gt;Install Vault with Helm&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#initialize-vault"&gt;Initialize Vault&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#expose-vault-to-the-outside"&gt;Expose Vault to the Outside&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#create-the-vault-secret-backend-for-odf"&gt;Create the Vault Secret Backend for ODF&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#configure-vault-policy"&gt;Configure Vault Policy&lt;/a&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#configure-odf-on-the-spoke-cluster"&gt;Configure ODF on the Spoke Cluster&lt;/a&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;a href="#create-serviceaccount-in-the-tenant-namespace"&gt;Create ServiceAccount in the Tenant Namespace&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#create-serviceaccount-and-rbac-for-odf"&gt;Create ServiceAccount and RBAC for ODF&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#configure-kms-connectivity-for-odf"&gt;Configure KMS Connectivity for ODF&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#configure-vault-kubernetes-authentication"&gt;Configure Vault Kubernetes Authentication&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#create-the-encrypted-storageclass"&gt;Create the Encrypted StorageClass&lt;/a&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#test-the-encryption"&gt;Test the Encryption&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#conclusions"&gt;Conclusions&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="introduction"&gt;Introduction&lt;/h2&gt;&#10;&lt;p&gt;Data security is a critical concern in any production environment, especially when sensitive workloads run on shared infrastructure. OpenShift Data Foundation (ODF) supports Persistent Volume (PV) encryption at rest using an external Key Management System (KMS). One of the most common and powerful options for this is HashiCorp Vault.&lt;/p&gt;</description></item></channel></rss>