Skip to content

Set up IDB/HDB encryption parameters

This page describes the IDB/HDB encryption parameters defined across systemParams.yaml, schema.yaml, and hdbTiers.yaml.

IDB/HDB encryption parameters are defined in the following configuration objects:

  • systemParams.yaml
  • schema.yaml
  • hdbTiers.yaml

systemParams.yaml

General encryption parameters

In this configuration object, general IDB/HDB encryption parameters are defined.

- name: dbEncrEnabled
  type: bool
  description: Encrypt all on-disk data that is configured as such
  value: false
  dynamic: true
- name: encrTblCats
  type: symbs
  description: Table categories to be encrypted
  value: all
  dynamic: true
- name: symEncrypted
  type: bool
  description: Specifies if the symbol file should be encrypted on-disk
  value: true
  dynamic: true
- name: idbEncrypted
  type: bool
  description: Specifies if the IDB should be encrypted, including snapshot tables
  value: true
  dynamic: true
- name: hdbEncrypted
  type: bool
  description: Specifies if the HDB should be encrypted, including all tiers
  value: true
  dynamic: true
- name: encrBlock
  type: int
  description: Logical block size used for encryption. Overridden by compression LBS settings if compression is also enabled
  value: 17
  dynamic: true
Attribute Description Default
dbEncrEnabled If enabled, KXS encrypts all IDB/HDB data subject to any restrictions specified in the parameters below. If not enabled, no encryption will occur regardless of your IDB, HDB and sym encryption parameters. When KXS processes start up and encryption is enabled, the encryption master key is automatically loaded, which allows the relevant processes to write encrypted data to or read encrypted data from disk. false
encrTblCats The list of table categories to be encrypted. Individual table categories are entered in the form of a comma-separated list. If set to "all" or empty, all table categories are encrypted. all
symEncrypted Whether or not the on-disk symbol file is encrypted. true
idbEncrypted Whether or not IDB including table snapshots are encrypted. true
hdbEncrypted Whether or not HDB including all tiers (subject to tier configuration) are encrypted. true
encrBlock The logical block size kdb+ uses when encrypting data. When both encrypting and compressing at the same time, the logical block size specified by the compression settings in hdbTiers.yaml overrides the encrBlock value. 17

Master key and password file location

In this configuration object, the file location of both the master key file and the master key password file are also defined. Changing these parameters requires a system restart.

- name: masterKeyFile
  type: hsym
  description: Encryption master key file
  value: ${MISC}/master.key
  dynamic: false
- name: masterKeyPassFile
  type: hsym
  description: Encrypted master key password file
  value: ${MISC}/master.key.pass
  dynamic: false

schema.yaml

In a schema YAML, individual table columns can be selected for encryption by means of the isEncrypted flag. By default, isEncrypted is set to true for columns where the flag is not specified. Encryption can be turned off by setting the flag to false. In this example, column1 and column2 are encrypted, and column3 is not:

Example:
  m-meta: schema.yaml
  type: partitionedDelta
  groups: SD
  columns:
  - name: column1
    type: integer
    isEncrypted: true
  - name: column2
    type: timestamp
    isEncrypted: true
  - name: column3
    type: short
    isEncrypted: false

hdbTiers.yaml

In this configuration object, individual HDB tiers can be selected for encryption. This object inherits any restrictions that are defined in systemParams.yaml. For example, if encryption is restricted by table category and column, only those table categories and column names are encrypted in the tier.

Attribute Description Default
isEncrypted Whether the database tier is encrypted or not. 1b

In this example, the first two tiers are unencrypted, and the last two tiers are encrypted (the last tier relies on the default isEncrypted value of 1b):

hdbTiers:
  values:
    /root/kxs/db/hdb/data:
      parts: 5
      isEncrypted: false
    /root/kxs/db/compressed:
      parts: 5
      isEncrypted: false
      cmprAlg: 2
      cmprBlock: 17
      cmprLevel: 9
    /root/kxs/db/encrypted:
      parts: 5
    /root/kxs/db/cmprEncr:
      parts: 0
      cmprAlg: 4
      cmprBlock: 17
      cmprLevel: 9

Next steps