对于 AI 代理:可在 https://www.mongodb.com/zh-cn/docs/llms.txt 获取文档索引—通过在任何 URL 路径后添加 .md 可获取所有页面的 Markdown 版本。
Docs 菜单

使用密钥管理服务加密数据

Atlas默认会对所有集群存储和快照卷进行静态加密。您可以将云提供商的KMS与MongoDB加密存储引擎结合使用,再增加一个安全层。

您可以使用以下一个或多个客户KMS提供商在 Atlas 中进行静态加密:

注意

密钥管理提供商无需与集群云服务提供商匹配。

要了解有关将KMS与 Atlas 结合使用的更多信息,请参阅:

要使用Atlas Kubernetes Operator管理KMS加密,您可以指定并更新AtlasProject 自定义资源的 spec.encryptionAtRest 参数。每次更改任何支持的自定义资源中的 spec字段时, Atlas Kubernetes Operator都会创建或更新相应的Atlas配置。

要使用Amazon Web ServicesKMS 中的Atlas Kubernetes Operator 配置静态静态加密,您需要:

重要

如果将加密密钥切换为基于角色的访问权限,就无法撤销基于角色的访问权限配置,也无法恢复该项目上基于档案的加密密钥访问权限。

要在 中使用Google Cloud PlatformKMS Atlas Kubernetes Operator配置静态静态加密,您需要:

通过以下步骤,使用客户托管的密钥加密您的 Atlas 数据:

1

使用以下参数的值创建密钥:

Parameter
说明

CustomerMasterKeyID

唯一的字母数字字符串,用于标识您用于加密和解密 MongoDB 主密钥的Amazon Web Services客户主密钥。

RoleID

唯一的Amazon Web Services ARN ,用于标识有权管理客户主密钥的Amazon Web Services IAMAmazon Web Services角色。 要查找该值,请执行以下操作:

  1. Go到Amazon Web Services管理控制台的Roles部分。

  2. 单击您为Atlas访问权限编辑或创建的IAM角色。

AWS 在 Summary 部分显示 ARN。

要创建并标记密钥,请使用您的Amazon Web Services凭证运行以下命令:

kubectl create secret generic aws-ear-creds \
--from-literal="CustomerMasterKeyID=<customer-master-key>" \
--from-literal="RoleID=<aws-arn>" \
-n mongodb-atlas-system
kubectl label secret aws-ear-creds atlas.mongodb.com/type=credentials -n mongodb-atlas-system
2
  1. 将 spec.encryptionAtRest.awsKms 对象添加到 spec.encryptionAtRestAtlasProject 自定义资源中的数组,包括以下参数:

    Parameter
    说明

    spec.encryptionAtRest.awsKms.enabled

    指示此项目是否使用 AWS KMS静态数据的标志。要使用 AWS KMS启用静态加密,请将此参数设立为 true。要使用 AWS KMS禁用静态加密,请将此参数设立为 false。如果您使用 AWS KMS禁用静态加密, Atlas Kubernetes Operator会删除配置详细信息。

    spec.encryptionAtRest.awsKms.region

    指示客户主密钥所在Amazon Web Services区域的标签。

    spec.encryptionAtRest.awsKms.secretRef.name

    包含Amazon Web Services凭证的密钥名称。

    spec.encryptionAtRest.awsKms.secretRef.namespace

    包含 AWS凭证的命名空间。如果未指定,此参数默认为 AtlasProject 自定义资源的命名空间。

    您必须使用包含 AccessKeyID、SecretAccessKey 、CustomerMasterKeyID 和RoleID 值的密钥。

  2. 运行以下命令:

    cat <<EOF | kubectl apply -f -
    apiVersion: atlas.mongodb.com/v1
    kind: AtlasProject
    metadata:
    name: my-project
    spec:
    name: Test Atlas Operator Project
    encryptionAtRest:
    awsKms:
    enabled: true
    region: US_EAST_1
    secretRef:
    name: aws-ear-creds
    namespace: mongodb-atlas-system
    EOF
3

运行以下命令,检查Atlas Kubernetes Operator是否检测到项目的Amazon Web Services KMS配置。

kubectl get atlasprojects my-project -n mongodbatlas-system -o=jsonpath='{.status.conditions[?(@.type=="EncryptionAtRestReady")].status}'
true
4

使用客户托管的密钥为项目启用静态加密后,必须在集群级别启用静态加密才能加密数据。

运行以下命令,将 spec.deploymentSpec.encryptionAtRestProvider 添加到 AtlasDeployment 自定义资源,从而使用您的 AWS 密钥为此集群启用静态加密:

cat <<EOF | kubectl apply -f -
apiVersion: atlas.mongodb.com/v1
kind: AtlasDeployment
metadata:
name: my-cluster
spec:
name: Test Atlas Operator Cluster
DeploymentSpec:
encryptionAtRestProvider: "AWS"
EOF
1

使用以下参数的值创建密钥:

Parameter
说明

KeyIdentifier

带有标识Azure Key Vault 的唯一密钥的解决。

KeyVaultName

stringAzure标识包含密钥的 Key Vault 的唯一 。

Secret

与在 spec.encryptionAtRest.azureKeyVault.tenantID 中指定的Azure Key Vault租户关联的私有数据。

SubscriptionID

唯一的 36-十六进制string ,用于标识您的Azure订阅。 Azure在订阅的详细信息页面上显示订阅ID 。

要创建并标记密钥,请使用您的Azure凭证运行命令:

kubectl create secret generic azure-ear-creds \
--from-literal="KeyIdentifier=<web-address>" \
--from-literal="KeyVaultName=<key-vault>" \
--from-literal="Secret=<secret>" \
--from-literal="SubscriptionID=<subscription>" \
-n mongodb-atlas-system
kubectl label secret azure-ear-creds atlas.mongodb.com/type=credentials -n mongodb-atlas-system
2
  1. 添加 spec.encryptionAtRest.azureKeyVault对象的 spec.encryptionAtRestAtlasProject 自定义资源中的数组,包括以下参数:

    Parameter
    说明

    spec.encryptionAtRest.azureKeyVault.azureEnvironment

    Azure帐户凭证所在的Azure部署位置。有效值包括 AZURE、AZURE_CHINA 和 AZURE_GERMANY。

    spec.encryptionAtRest.azureKeyVault.clientID

    唯一的 36-十六进制string,用于标识您的 Azure 应用程序。

    spec.encryptionAtRest.azureKeyVault. enabled

    指示此项目是否使用Azure Key Vault静态数据的标志。要使用Azure Key Vault启用静态加密,请将此参数设立为 true。要使用Azure Key Vault禁用静态加密,请将此参数设立为 false。如果使用Azure Key Vault 禁用静态加密, Atlas Kubernetes Operator会删除配置详细信息。

    spec.encryptionAtRest.azureKeyVault.resourceGroupName

    用于标识包含 Azure Key Vault 的 Azure 资源组的标签。Azure在资源组的详细信息页面显示资源组名称。

    spec.encryptionAtRest.azureKeyVault.secretRef.name

    包含Azure的密钥名称。

    spec.encryptionAtRest.azureKeyVault.secretRef.namespace

    包含Azure凭证的命名空间。如果未指定,此参数默认为 AtlasProject 自定义资源的命名空间。

    spec.encryptionAtRest.azureKeyVault. tenantID

    唯一的 36-十六进制string,用于标识Azure订阅中的Azure Active Directory 租户。Azure在租户属性页面上显示租户ID 。

    您必须使用包含 KeyVaultName、KeyIdentifier 、Secret 和SubscriptionID 值的密钥。

  2. 运行以下命令:

    cat <<EOF | kubectl apply -f -
    apiVersion: atlas.mongodb.com/v1
    kind: AtlasProject
    metadata:
    name: my-project
    spec:
    name: Test Atlas Operator Project
    encryptionAtRest:
    azureKeyVault:
    azureEnvironment: AZURE
    clientID: "12345678-90ab-cdef-1234-567890abcdef"
    enabled: true
    resourceGroupName: "myResourceGroup"
    tenantID: "e8e4b6ba-ff32-4c88-a9af-EXAMPLEID"
    secretRef:
    name: azure-ear-creds
    namespace: mongodb-atlas-system
    EOF
3

运行以下命令,检查Atlas Kubernetes Operator是否检测到项目的Azure Key Vault 配置。

kubectl get atlasprojects my-project -o=jsonpath='{.status.conditions[?(@.type=="EncryptionAtRestReadyType")].status}
true
4

使用客户托管的密钥为项目启用静态加密后,必须在集群级别启用静态加密才能加密数据。

运行以下命令,将 spec.deploymentSpec.encryptionAtRestProvider 添加到您的 AtlasDeployment 自定义资源 中,从而使用您的 Azure 密钥为此集群启用静态加密:

cat <<EOF | kubectl apply -f -
apiVersion: atlas.mongodb.com/v1
kind: AtlasDeployment
metadata:
name: my-cluster
spec:
name: Test Atlas Operator Cluster
DeploymentSpec:
encryptionAtRestProvider: "AZURE"
EOF
1

使用以下参数的值创建密钥:

Parameter
说明

KeyVersionResourceID

显示 的密钥版本资源ID Google Cloud PlatformKMS的唯一资源路径。

ServiceAccountKey

JSON文件,其中包含Google Cloud PlatformKMS 帐户的Google Cloud Platform 凭证。

重要提示:您必须正确设置JSON对象的格式。 确保文件中的凭证字段正确缩进。

以下示例显示了ServiceAccountKey JSON文件的内容:

{
"type": "service_account",
"project_id": "my-project-common-0",
"private_key_id": "e120598ea4f88249469fcdd75a9a785c1bb3\",
"private_key": "-----BEGIN PRIVATE KEY-----\\nMIIEuwIBA(truncated)SfecnS0mT94D9\\n-----END PRIVATE KEY-----\\n\",
"client_email": "my-email-kms-0@my-project-common-0.iam.gserviceaccount.com\",
"client_id": "10180967717292066",
"auth_uri": "https://accounts.google.com/o/oauth2/auth",
"token_uri": "https://accounts.google.com/o/oauth2/token",
"auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
"client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/my-email-kms-0%40my-project-common-0.iam.gserviceaccount.com"
"universe_domain": "googleapis.com"
}

要创建并标记密钥,请使用您的Google Cloud Platform凭证运行以下命令:

kubectl create secret generic azure-ear-creds \
--from-literal="KeyVersionResourceID=<resource-id>" \
--from-file="ServiceAccountKey=<your-service-account-key-files.json>" \
-n mongodb-atlas-system
kubectl label secret gcp-ear-creds atlas.mongodb.com/type=credentials -n mongodb-atlas-system
2
  1. 添加 spec.encryptionAtRest.googleCloudKms对象的 spec.encryptionAtRestAtlasProject 自定义资源中的数组,包括以下参数:

    Parameter
    说明

    spec.encryptionAtRest.googleCloudKms.enabled

    指示此项目是否使用 Google Cloud KMS对静态数据进行加密的标志。要使用 Google Cloud KMS启用静态加密,请将此参数设立为 true。要使用 Google Cloud KMS禁用静态加密,请将此参数设立为 false。如果您使用 Google Cloud KMS禁用静态加密, Atlas Kubernetes Operator会删除配置详细信息。

    spec.encryptionAtRest.googleCloudKms.secretRef.name

    包含Google Cloud Platform凭证的密钥名称。

    spec.encryptionAtRest.googleCloudKms.secretRef.namespace

    包含您的 Google Cloud Platform 档案的命名空间。如果未指定,此参数默认为AtlasProject自定义资源的命名空间。

    You must use a secret that contains the values for KeyVersionResourceID and ServiceAccountKey.

  2. 运行以下命令:

    cat <<EOF | kubectl apply -f -
    apiVersion: atlas.mongodb.com/v1
    kind: AtlasProject
    metadata:
    name: my-project
    spec:
    name: Test Atlas Operator Project
    encryptionAtRest:
    googleCloudKms:
    enabled: true
    secretRef:
    name: gcp-ear-creds
    namespace: mongodb-atlas-system
    EOF
3

运行以下命令,检查Atlas Kubernetes Operator是否检测到项目的Google Cloud Platform KMS配置。

kubectl get atlasprojects my-project -o=jsonpath='{.status.conditions[?(@.type=="EncryptionAtRestReadyType")].status}
true
4

使用客户托管的密钥为项目启用静态加密后,必须在集群级别启用静态加密才能加密数据。

运行以下命令,将 spec.deploymentSpec.encryptionAtRestProvider 添加到您的 AtlasDeployment 自定义资源中,从而使用您的 Google Cloud 密钥为此集群启用静态加密:

cat <<EOF | kubectl apply -f -
apiVersion: atlas.mongodb.com/v1
kind: AtlasDeployment
metadata:
name: my-cluster
spec:
name: Test Atlas Operator Cluster
DeploymentSpec:
encryptionAtRestProvider: "GCP"
EOF
给本页内容打分

在此页面上