Details
-
Task
-
Status: Open (View Workflow)
-
Major
-
Resolution: Unresolved
-
None
Description
We should document how to safely disable InnoDB encryption in a Galera Cluster environment. It is not currently documented:
https://mariadb.com/kb/en/library/data-at-rest-encryption/
https://mariadb.com/kb/en/library/galera-cluster/
I suspect that the process would go like this:
1.) Stop all nodes in the cluster except 1.
2.) Make sure that all Aria tables are decrypted. Requires MDEV-17268.
3.) Make sure that all InnoDB tables are decrypted. Requires MDEV-17269.
4.) Make sure that InnoDB redo logs are decrypted. Requires MDEV-17270.
5.) Make sure that binary logs are decrypted. Requires MDEV-17271.
6.) Uninstall key management plugins, if desired.
7.) Force other nodes to SST using a physical SST method, such as mariabackup, rsync, xtrabackup-v2.
https://mariadb.com/kb/en/library/getting-started-with-mariadb-galera-cluster/#sst-scripts
Attachments
Issue Links
- is blocked by
-
MDEV-17268 Document how to safely decrypt Aria tables
- Closed
-
MDEV-17269 Document how to safely decrypt InnoDB tables
- Closed
-
MDEV-17270 Document how to safely disable innodb_encrypt_log
- Closed
-
MDEV-17271 Document how to safely disable encrypt_binlog
- Closed
- relates to
-
MDEV-14157 Improve documentation of data at rest encryption
- Closed
- blocks
-
DOCS-2785 Loading...