إنتقل إلى المحتوى الرئيسي
ينطبق على:
DuoKey Cockpit v2Nutanix AHV Data-at-Rest Encryption (DARE)KMIP external key manager

Overview​

Nutanix AHV's Data-at-Rest Encryption (DARE) has a built-in KMIP client: once you register an "external key manager" in Prism, the cluster creates and registers an AES-256 encryption key with that manager over binary KMIP, then retrieves it at boot to unlock the cluster's storage. DuoKey's Nutanix VM Encryption integration makes Cockpit that external key manager — the same KMIP-based key custody model used elsewhere in DuoKey's database and infrastructure integrations, applied here to Nutanix's cluster-encryption workflow.

Nutanix AHV to the DuoKey KMIP server
Nutanix AHV clusterPrism / ncli — DARE KMIP clientCluster-wide or per-storage-container scope
KMIP (TTLV) over mutual TLS — port 5696
DuoKey KMIP serverCockpit's KMIP listener — Create / Register / Get / Activate
seal / unseal
Tenant vault / HSMAES-256 cluster encryption key sealed at rest

The cluster's DARE KMIP client talks directly to the Cockpit's KMIP listener; the cluster encryption key never leaves DuoKey custody.

There is no setup wizard for this integration: you register the cluster's connection details directly, then generate a deployment bundle to hand to the Nutanix operator.

Cockpit tracks the pairing, not the cluster

Cockpit records which Nutanix cluster is bound to which key and KMIP endpoint, and generates the onboarding commands. Enabling encryption on the cluster itself is a Prism / ncli operation the Nutanix operator runs — DuoKey does not reach into the cluster to enable it.

Configuration​

FieldPurpose
Prism host / portThe Prism Central or Prism Element management endpoint, recorded for operator reference. The actual key exchange runs over binary KMIP, not this REST endpoint.
Cluster UUIDThe target AHV cluster to bind.
Cluster nameOptional friendly name.
Protection scopeEither cluster — one key protects every storage container — or storage_container — a distinct key per named container.
Storage containersThe list of storage containers to protect individually, when the scope is per-container.
KMIP portThe binary KMIP (TTLV/mTLS) port the cluster dials — 5696 by default.
Key rotation daysOptional target rotation interval for the cluster encryption key.
VaultThe DuoKey vault that holds the AES-256 cluster encryption key. Defaults to the tenant vault when not specified.

Key lifecycle​

StateMeaning
pre_activeThe key exists in the vault but is not yet the cluster's active DARE key.
activeThe cluster unlocks with this key at boot.
revokedThe key has been revoked; the cluster must be re-keyed before it can be trusted again.
destroyedThe key material has been destroyed.

Onboarding a cluster​

Cluster onboarding, at a glance
1. Register DuoKey as external KMSncli data-at-rest-encryption-config add-external-kms — Prism trusts Cockpit's KMIP listener
KMIP Create / Register — TTLV over mutual TLS, port 5696
2. Cluster creates and registers the keyncli data-at-rest-encryption-config create-key — DuoKey issues the AES-256 key and activates it
seal / unseal
3. Key sealed in the DuoKey vaultCluster encryption key custodied outside the cluster
ncli data-at-rest-encryption-config enable
4. Prism enables Data-at-Rest EncryptionCluster unlocks storage with the registered key at boot

Steps 1 and 3 run the ncli commands generated by the deployment bundle; DuoKey never reaches into the cluster to run them.

1

Register the cluster

Provide the Prism endpoint, cluster UUID, protection scope, and — for per-container scope — the storage container names. DuoKey creates the AES-256 cluster encryption key in the linked vault.

2

Generate the deployment bundle

DuoKey returns the KMIP connection details (host, port, and the mTLS client certificate / key / CA paths the cluster needs) plus an ordered list of ncli commands for the Nutanix operator.

3

Run the onboarding commands on the cluster

Register DuoKey's KMIP listener as an external key manager, create and enable the encryption key (cluster-wide or per storage container), then verify.

4

Confirm encryption is active

Check the cluster's Data-at-Rest Encryption status in Prism, and the key's state in DuoKey (it should move to active).

Example onboarding commands (cluster-wide protection scope)BASH
# 1. Register DuoKey's KMIP listener as the cluster's external key manager
ncli data-at-rest-encryption-config add-external-kms name=dke_cockpit \
kmip-host=<kmip-host> kmip-port=<kmip-port> \
client-certificate-path=<client-cert-path> \
client-key-path=<client-key-path> \
ca-certificate-path=<ca-cert-path>

# 2. Create the cluster-wide encryption key on the external key manager
ncli data-at-rest-encryption-config create-key key-name=<key-label> kms-name=dke_cockpit

# 3. Enable Data-at-Rest Encryption using the registered key
ncli data-at-rest-encryption-config enable key-name=<key-label>

# 4. Verify
ncli data-at-rest-encryption-config get
Per-storage-container scope

When the protection scope is storage_container, there is no separate key-creation command: a single enable command with a container-scoped key name creates and activates the key together, repeated once per container instead of the single cluster-wide enable.

Health and connectivity​

The cluster's health check reports whether the integration is enabled, whether its encryption key is active, and a combined encryption-enabled indicator. A test-connection check validates the stored configuration and surfaces any configuration warnings before you generate the deployment bundle.

Configuration-derived status

Health results reflect the configuration and key state stored in DuoKey. Confirm the cluster's own Data-at-Rest Encryption status in Prism as the source of truth for whether encryption is actually active on the cluster.

Prerequisites​

المتطلبات المسبقة

  • A Nutanix AHV cluster with Prism access and permission to configure Data-at-Rest Encryption
  • Network reachability from the cluster to DuoKey Cockpit's KMIP listener over the configured KMIP port
  • A DuoKey vault to hold the AES-256 cluster encryption key
Choosing a protection scope

Use cluster-wide protection unless you specifically need independent key rotation or revocation per storage container — per-container scope adds one key (and one onboarding step) per container.