TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Encrypting Postgres Data at Rest in Kubernetes

108 点作者 plaur782超过 3 年前

5 条评论

speedgoose超过 3 年前
These automatically encrypted disks with managed keys in the clouds are nice to check the "encrypted at rest" checkbox for security audits but I think that they add little security. In most scenarios I can think of, both the data and the keys will be accessible to the attacker. And the ones where the attacker would have access to only the encrypted data seems very unlikely, like physical access to the data center with the knowledge of where is physically stored the data. But I would be gladly proven wrong.
评论 #29058691 未加载
评论 #29058317 未加载
评论 #29058329 未加载
评论 #29058268 未加载
评论 #29058322 未加载
评论 #29061601 未加载
评论 #29062335 未加载
评论 #29065509 未加载
评论 #29058569 未加载
sylr超过 3 年前
Am I the only one enforcing a strict no database in kubernetes policy ?
评论 #29058501 未加载
评论 #29058897 未加载
评论 #29058495 未加载
评论 #29061777 未加载
评论 #29061169 未加载
评论 #29059147 未加载
评论 #29058959 未加载
评论 #29059229 未加载
CamouflagedKiwi超过 3 年前
Was hoping for something a little more profound than "use an encrypted storageclass for your volumes".
评论 #29058852 未加载
handrous超过 3 年前
Tangentially related: what&#x27;s state-of-the-art for data protection &amp; access control for small organizations? One runs into the &quot;someone&#x27;s gotta be trusted with the master keys&quot; problem there so early &amp; often that all the &quot;big&quot; solutions feel silly. Do small shops just farm this out via SaaS and hope their provider&#x27;s doing the right thing?<p>(the answer back in the day, and perhaps still, was just &quot;they don&#x27;t really worry about it at all, and hope nothing goes wrong&quot;)
ianlevesque超过 3 年前
This post was really laying it on a bit thick on the marketing, with three mentions of their own products before even finishing the introduction. I know that’s the point of most of these posts but then when the content was also a product, it’s too much. Pass.