Set up IDB/HDB encryption parameters¶
This page describes the IDB/HDB encryption parameters defined across systemParams.yaml, schema.yaml, and hdbTiers.yaml.
IDB/HDB encryption parameters are defined in the following configuration objects:
systemParams.yamlschema.yamlhdbTiers.yaml
systemParams.yaml¶
General encryption parameters¶
In this configuration object, general IDB/HDB encryption parameters are defined.
- name: dbEncrEnabled
type: bool
description: Encrypt all on-disk data that is configured as such
value: false
dynamic: true
- name: encrTblCats
type: symbs
description: Table categories to be encrypted
value: all
dynamic: true
- name: symEncrypted
type: bool
description: Specifies if the symbol file should be encrypted on-disk
value: true
dynamic: true
- name: idbEncrypted
type: bool
description: Specifies if the IDB should be encrypted, including snapshot tables
value: true
dynamic: true
- name: hdbEncrypted
type: bool
description: Specifies if the HDB should be encrypted, including all tiers
value: true
dynamic: true
- name: encrBlock
type: int
description: Logical block size used for encryption. Overridden by compression LBS settings if compression is also enabled
value: 17
dynamic: true
| Attribute | Description | Default |
|---|---|---|
dbEncrEnabled |
If enabled, KXS encrypts all IDB/HDB data subject to any restrictions specified in the parameters below. If not enabled, no encryption will occur regardless of your IDB, HDB and sym encryption parameters. When KXS processes start up and encryption is enabled, the encryption master key is automatically loaded, which allows the relevant processes to write encrypted data to or read encrypted data from disk. | false |
encrTblCats |
The list of table categories to be encrypted. Individual table categories are entered in the form of a comma-separated list. If set to "all" or empty, all table categories are encrypted. | all |
symEncrypted |
Whether or not the on-disk symbol file is encrypted. | true |
idbEncrypted |
Whether or not IDB including table snapshots are encrypted. | true |
hdbEncrypted |
Whether or not HDB including all tiers (subject to tier configuration) are encrypted. | true |
encrBlock |
The logical block size kdb+ uses when encrypting data. When both encrypting and compressing at the same time, the logical block size specified by the compression settings in hdbTiers.yaml overrides the encrBlock value. |
17 |
Master key and password file location¶
In this configuration object, the file location of both the master key file and the master key password file are also defined. Changing these parameters requires a system restart.
- name: masterKeyFile
type: hsym
description: Encryption master key file
value: ${MISC}/master.key
dynamic: false
- name: masterKeyPassFile
type: hsym
description: Encrypted master key password file
value: ${MISC}/master.key.pass
dynamic: false
schema.yaml¶
In a schema YAML, individual table columns can be selected for encryption by means of the isEncrypted flag. By default, isEncrypted is set to true for columns where the flag is not specified. Encryption can be turned off by setting the flag to false. In this example, column1 and column2 are encrypted, and column3 is not:
Example:
m-meta: schema.yaml
type: partitionedDelta
groups: SD
columns:
- name: column1
type: integer
isEncrypted: true
- name: column2
type: timestamp
isEncrypted: true
- name: column3
type: short
isEncrypted: false
hdbTiers.yaml¶
In this configuration object, individual HDB tiers can be selected for encryption. This object inherits any restrictions that are defined in systemParams.yaml. For example, if encryption is restricted by table category and column, only those table categories and column names are encrypted in the tier.
| Attribute | Description | Default |
|---|---|---|
isEncrypted |
Whether the database tier is encrypted or not. | 1b |
In this example, the first two tiers are unencrypted, and the last two tiers are encrypted (the last tier relies on the default isEncrypted value of 1b):
hdbTiers:
values:
/root/kxs/db/hdb/data:
parts: 5
isEncrypted: false
/root/kxs/db/compressed:
parts: 5
isEncrypted: false
cmprAlg: 2
cmprBlock: 17
cmprLevel: 9
/root/kxs/db/encrypted:
parts: 5
/root/kxs/db/cmprEncr:
parts: 0
cmprAlg: 4
cmprBlock: 17
cmprLevel: 9