Environment and Cloudera Data Hub encryption options

By default, Cloudera Data Hub clusters use the same default key from Amazon’s KMS or CMK as the parent environment, but you have an option to pass a different CMK during Cloudera Data Hub creation.

The following table summarizes all possible scenarios:

Table 1. Environment and Cloudera Data Hub encryption scenarios
Encryption key during environment registration Encryption key during Cloudera Data Hub creation Result

Absent

Absent

EBS and RDS encryption for FreeIPA and Cloudera Data Hub clusters is with the default regional encryption key.

Present

Absent

EBS and RDS encryption for FreeIPA and all Cloudera Data Hub clusters is with the CMK provided during environment registration.

Present

Present

EBS and RDS encryption for FreeIPA is with the CMK provided during environment registration.

If a CMK is provided for a Cloudera Data Hub then EBS encryption for the Cloudera Data Hub is with the CMK provided per host group during the Cloudera Data Hub creation.

Absent

Present

No EBS and RDS encryption is configured for FreeIPA.

EBS encryption for the specific Cloudera Data Hub is with the default or CMK provided per host group during Cloudera Data Hub creation.