Nutanix VM Encryption
Register DuoKey as the external key manager behind Nutanix AHV's Data-at-Rest Encryption.
Overview
Nutanix AHV's Data-at-Rest Encryption (DARE) has a built-in KMIP client: once you register an "external key manager" in Prism, the cluster creates and registers an AES-256 encryption key with that manager over binary KMIP, then retrieves it at boot to unlock the cluster's storage. DuoKey's Nutanix VM Encryption integration makes Cockpit that external key manager — the same KMIP-based key custody model used elsewhere in DuoKey's database and infrastructure integrations, applied here to Nutanix's cluster-encryption workflow.
The cluster's DARE KMIP client talks directly to the Cockpit's KMIP listener; the cluster encryption key never leaves DuoKey custody.
There is no setup wizard for this integration: you register the cluster's connection details directly, then generate a deployment bundle to hand to the Nutanix operator.
Cockpit records which Nutanix cluster is bound to which key and KMIP endpoint, and generates the onboarding commands. Enabling encryption on the cluster itself is a Prism / ncli operation the Nutanix operator runs — DuoKey does not reach into the cluster to enable it.
Configuration
| Field | Purpose |
|---|---|
| Prism host / port | The Prism Central or Prism Element management endpoint, recorded for operator reference. The actual key exchange runs over binary KMIP, not this REST endpoint. |
| Cluster UUID | The target AHV cluster to bind. |
| Cluster name | Optional friendly name. |
| Protection scope | Either cluster — one key protects every storage container — or storage_container — a distinct key per named container. |
| Storage containers | The list of storage containers to protect individually, when the scope is per-container. |
| KMIP port | The binary KMIP (TTLV/mTLS) port the cluster dials — 5696 by default. |
| Key rotation days | Optional target rotation interval for the cluster encryption key. |
| Vault | The DuoKey vault that holds the AES-256 cluster encryption key. Defaults to the tenant vault when not specified. |
Key lifecycle
| State | Meaning |
|---|---|
| pre_active | The key exists in the vault but is not yet the cluster's active DARE key. |
| active | The cluster unlocks with this key at boot. |
| revoked | The key has been revoked; the cluster must be re-keyed before it can be trusted again. |
| destroyed | The key material has been destroyed. |
Onboarding a cluster
Steps 1 and 3 run the ncli commands generated by the deployment bundle; DuoKey never reaches into the cluster to run them.
Register the cluster
Provide the Prism endpoint, cluster UUID, protection scope, and — for per-container scope — the storage container names. DuoKey creates the AES-256 cluster encryption key in the linked vault.
Generate the deployment bundle
DuoKey returns the KMIP connection details (host, port, and the mTLS client certificate / key / CA paths the cluster needs) plus an ordered list of ncli commands for the Nutanix operator.
Run the onboarding commands on the cluster
Register DuoKey's KMIP listener as an external key manager, create and enable the encryption key (cluster-wide or per storage container), then verify.
Confirm encryption is active
Check the cluster's Data-at-Rest Encryption status in Prism, and the key's state in DuoKey (it should move to active).
# 1. Register DuoKey's KMIP listener as the cluster's external key manager
ncli data-at-rest-encryption-config add-external-kms name=dke_cockpit \
kmip-host=<kmip-host> kmip-port=<kmip-port> \
client-certificate-path=<client-cert-path> \
client-key-path=<client-key-path> \
ca-certificate-path=<ca-cert-path>
# 2. Create the cluster-wide encryption key on the external key manager
ncli data-at-rest-encryption-config create-key key-name=<key-label> kms-name=dke_cockpit
# 3. Enable Data-at-Rest Encryption using the registered key
ncli data-at-rest-encryption-config enable key-name=<key-label>
# 4. Verify
ncli data-at-rest-encryption-config getWhen the protection scope is storage_container, there is no separate key-creation command: a single enable command with a container-scoped key name creates and activates the key together, repeated once per container instead of the single cluster-wide enable.
Health and connectivity
The cluster's health check reports whether the integration is enabled, whether its encryption key is active, and a combined encryption-enabled indicator. A test-connection check validates the stored configuration and surfaces any configuration warnings before you generate the deployment bundle.
Health results reflect the configuration and key state stored in DuoKey. Confirm the cluster's own Data-at-Rest Encryption status in Prism as the source of truth for whether encryption is actually active on the cluster.
Prerequisites
Prérequis
- A Nutanix AHV cluster with Prism access and permission to configure Data-at-Rest Encryption
- Network reachability from the cluster to DuoKey Cockpit's KMIP listener over the configured KMIP port
- A DuoKey vault to hold the AES-256 cluster encryption key
Use cluster-wide protection unless you specifically need independent key rotation or revocation per storage container — per-container scope adds one key (and one onboarding step) per container.