Encrypting existing volumes
The online volume encryption feature lets you migrate unencrypted volumes at rest to encrypted ones. Using this feature a volume is migrated without application downtime, that is, while the file system is mounted and while the I/Os are running. The online migration operation involves mirroring the existing storage configured under a volume, which requires an equal amount of additional storage that gets used in the background.
This feature is available only with:
-
InfoScale 9.0 and later on:
-
Linux managed hosts
-
Linux and Windows for Central Management Server (CMS)
-
-
InfoScale Operations Manager Management Server 9.0 and later
Online migration involves the Start phase, in which the process is initiated, and the Commit phase, in which the background changes made to the volume are finalized. The unencrypted volume is migrated to an encrypted one when both these phases are completed successfully. After the Start phase is complete and before you can initiate the Commit phase, you can abort the migration or switch plexes. The switching of reads between the source (unencrypted) plex and the target (unencrypted) plex helps verify the data copied during the Start phase. Meanwhile, the writes continue to happen on both the plexes.
Limitations:
-
Encryption of RAID 5 and erasure coded (EC) volumes is not supported on Linux hosts.
-
Only one online migration can be performed on an unencrypted volume at a time.
-
Only one top-level mirror plex can be migrated at a time.
The volume encryption operations can be launched from the context of an existing unencrypted volume. To perform these operations, your user group must be assigned the admin role on the host or in the Server perspective. The permission on the host may be explicitly assigned or inherited from a parent Organization.
Figure: Menus for encrypting an existing unencrypted volume
Online migration involves the following operations:
Each of these operations invokes an InfoScale command in the background, and you can view the status of each operation in the Recent Tasks pane.
For details on the volume encryption feature and the related commands, refer to the platform-specific Storage Foundation Administrator's Guide.
To troubleshoot any issues that you may encounter while performing these operations, you can review the information logged in the following InfoScale Operations Manager files:
-
Management Server logs:
WebDebugLog.txtandtomcat.log -
Agent log:
mhrun.log