Data key rotation in Yugabyte DB

Viewed 89

From the encryption at rest design document in Github, only the Universe Keys are rotated while the data keys remain unchanged for the lifetime of the data file.

However, the Yugabyte docs mention that "Old data will remain unencrypted, or encrypted, with an older key, until compaction churn triggers a re-encryption with the new key.".

  1. Does this mean that the data keys implicitly get rotated when doing compaction?

  2. And we can force this compaction (and data key rotation) by triggering a manual compaction via the yb-admin tool?

1 Answers

Each data file contains a reference to the key id of the master side key used to encrypt its file-level data key, so technically even after a master key rotation we may have older sst files which reference the old key. So if you want no older data files to reference the old key after a rotation, you will have to do a manual compaction.

Related