camunda / issues

4 stars 0 forks source link

Camunda-Managed Encryption Keys in C8 SaaS #801

Open engineering-issue-sync-app[bot] opened 5 months ago

engineering-issue-sync-app[bot] commented 5 months ago

Value Proposition Statement

Increased security by a dedicated disk encryption key for your cluster for data at rest.

User Problem

Release Notes

You can now decide for advanced encryption key mechanisms on C8 SaaS when creating new clusters. Besides default GCP disk encryption, you can now choose between Software and Hardware Keys (HSM) managed by Camunda on GCP KMS. You can do this per cluster, meaning every cluster has a dedicated encryption key.

User Stories

Implementation Notes

What we are looking to offer as an option would be something like this:

Per default everything stays the same - using for clusters the GCP default encryption.

For Enterprise customers, they can choose to create a Camunda cluster using a dedicated encryption key

:robot: This issue is automatically synced from: source

mesellings commented 2 months ago

@Sijoma Published to https://docs.camunda.io/docs/next/components/concepts/encryption-at-rest/

mesellings commented 1 month ago

Closed this as not sure why it was reopened by the bot?