Introduce a new SLS Oplog message for encrypted KEKs

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Fixed
    • Priority: Major - P3
    • 8.3.0-rc0
    • Affects Version/s: None
    • Component/s: None
    • None
    • Server Security
    • Fully Compatible
    • Server Security 2026-01-16, Server Security 2026-01-30, Server Security 2026-02-13
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      When rotating to a new KEK, we need to dump the encrypted KEK object out to the oplog specifically for PIT restore, since PIT restore starts at a checkpoint and then uses the oplog to jog the system to a specific point-in-time. The oplog therefore needs to have the encrypted KEK to decrypt future oplog messages encrypted with the new KEK.

            Assignee:
            Shreyas Kalyan
            Reporter:
            Shreyas Kalyan
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: