Uploaded image for project: 'Documentation'
  1. Documentation
  2. DOCS-13932

[OM] Improve description on how Encrypted Snapshots are taken for FCV 4.2

    • Type: Icon: Task Task
    • Resolution: Fixed
    • Priority: Icon: Major - P3 Major - P3
    • None
    • Affects Version/s: None
    • Component/s: Ops Manager
    • Labels:

      Description

      https://jira.mongodb.org/browse/HELP-19346 raised by a TSE engineer mentioned how the current docs page for Encrypted Snapshots do not contain sufficient explanation on how a Snapshot is encrypted for FCV 4.2.

      Page: https://docs.opsmanager.mongodb.com/v4.4/tutorial/encrypt-snapshots/

      I would suggest to add the following chunk of text to the fcv 4.2 or greater to supplement the existing text.

      This should be backported to Ops Manager 4.2 docs as well.

      Thanks,
      Steven

      ____________

      Backups for FCV 4.2 occur by copying the bytes on disk from the replica set node’ dbpath and saving them into the snapshot store. If a node has MongoDB Encryption at Rest enabled, then the bytes that we copy are already encrypted as Encryption at Rest performs encryption at the Storage Engine layer when writing the bytes on to disk. For FCV 4.2, in the Snapshot process, there are no Ops Manager components that interact with the KMIP server. However, the Backup Daemon will require a connection to the KMIP server to process a Queryable Restore Job.

      Scope of changes

      Impact to Other Docs

      MVP (Work and Date)

      Resources (Scope or Design Docs, Invision, etc.)

            Assignee:
            john.williams@mongodb.com John Williams
            Reporter:
            steven.connors@mongodb.com Steven Connors (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved:
              3 years, 25 weeks, 1 day ago