diff --git a/examples/crypto/secret-crypto-customized-rhel-FIPS-enabled.yaml b/examples/crypto/secret-crypto-customized-rhel-FIPS-enabled.yaml new file mode 100644 index 0000000..4157af7 --- /dev/null +++ b/examples/crypto/secret-crypto-customized-rhel-FIPS-enabled.yaml @@ -0,0 +1,13 @@ +--- +apiVersion: v1 +kind: Secret +metadata: + name: longhorn-crypto + namespace: longhorn-system +stringData: + CRYPTO_KEY_VALUE: "Simple passphrase" + CRYPTO_KEY_PROVIDER: "secret" # this is optional we currently only support direct keys via secrets + CRYPTO_KEY_CIPHER: "aes-cbc-essiv:sha256" # this is optional, default value for RHEL + CRYPTO_KEY_HASH: "sha256" # this is optional, default value + CRYPTO_KEY_SIZE: "256" # this is optional, default value + CRYPTO_PBKDF: "pbkdf2" # Only PBKDF2 is supported in FIPS mode, needs to be set on RHEL7 diff --git a/examples/crypto/secret-crypto-customized.yaml b/examples/crypto/secret-crypto-customized.yaml new file mode 100644 index 0000000..112fea2 --- /dev/null +++ b/examples/crypto/secret-crypto-customized.yaml @@ -0,0 +1,13 @@ +--- +apiVersion: v1 +kind: Secret +metadata: + name: longhorn-crypto + namespace: longhorn-system +stringData: + CRYPTO_KEY_VALUE: "Simple passphrase" + CRYPTO_KEY_PROVIDER: "secret" # this is optional we currently only support direct keys via secrets + CRYPTO_KEY_CIPHER: "aes-xts-plain64" # this is optional, default value + CRYPTO_KEY_HASH: "sha256" # this is optional, default value + CRYPTO_KEY_SIZE: "256" # this is optional, default value + CRYPTO_PBKDF: "argon2i" # this is optional, default value