Update the token if the encryption token for your key management system gets deleted or
expires.
Before you begin
Ensure that you have a new token with the same policy as the deleted or expired
token.
About this task
Use this procedure to update the token if the encryption token for your key management system
gets deleted or expires.
Procedure
- Log in to OpenShift Container Platform Web Console.
- Go to
.
- Update the ocs-kms-token used for cluster wide encryption.
- Set the Project to
openshift-storage
.
- Go to
.
- Drag and drop or upload your encryption token file in the Value
field.
The token can either be a file or text that can be copied and
pasted.
- Click Save.
- Update the ceph-csi-kms-token for a given project or namespace
with encrypted persistent volumes.
- Select the required Project.
- Go to
.
- Drag and drop or upload your encryption token file in the Value
field.
The token can either be a file or text that can be copied and
pasted.
- Click Save.
Note: The token can be deleted only after all the encrypted PVCs using the
ceph-csi-kms-token
have been deleted.