Enabling Data-at-Rest Encryption on existing production clusters - VMware vSAN ESA
search cancel

Enabling Data-at-Rest Encryption on existing production clusters - VMware vSAN ESA

book

Article ID: 447483

calendar_today

Updated On:

Products

VMware vSAN

Issue/Introduction

Guidance is required on how to safely enable vSAN Data-at-Rest Encryption on an active production vSAN Express Storage Architecture (ESA) cluster hosting running workloads without incurring downtime.

Environment

  • VMware vSAN 8.x
  • VMware vSAN 9.x
  • Key Management: Existing external Key Management Server (KMS) trusted cluster connection

Resolution

  • Data Preservation: Your data is preserved during this process. vSAN encrypts existing data in the background.
  • Rolling Reformat: A rolling reformat of all disks in the storage pool takes place as vSAN encrypts all data in the vSAN datastore.
  • Performance: While the operation is non-disruptive, you may observe a temporary increase in storage latency or a slight reduction in storage performance due to background resynchronization activity. This behavior is expected.
  • Risk: No data loss is expected provided the cluster is healthy and the enablement completes successfully.

Prerequisites and Best Practices: Before you proceed with enabling encryption, verify the following:

  1. Skyline Health: Ensure the vSAN Skyline Health checks report no critical health issues.
  2. Object Health: Confirm all vSAN objects are healthy/compliant and there are no active resynchronization tasks.
  3. KMS Accessibility: Verify the external Key Management Server (KMS) is healthy, reachable, and functioning correctly.
  4. Capacity: Ensure you have sufficient free capacity to accommodate temporary resynchronization activity.
  5. Maintenance Window: Perform the activity during a maintenance window to minimize the impact of temporary performance degradation on production workloads.
  6. Backups: Ensure you have a current backup of critical virtual machines available before making infrastructure changes.

Additional Information

Enable vSAN Encryption on Existing vSAN Cluster