Skip to content

Commit 26b93f1

Browse files
authored
Merge pull request #93101 from SNiemann15/ibmz_hw_based_encryption
[OSDOCS-11048] IBM Z - Add module for CEX hw encryption
2 parents 395fdb4 + c4e5daa commit 26b93f1

9 files changed

+255
-35
lines changed

installing/installing_ibm_z/upi/installing-ibm-z-kvm.adoc

Lines changed: 9 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -51,7 +51,9 @@ include::modules/installation-user-infra-generate-k8s-manifest-ignition.adoc[lev
5151

5252
include::modules/installation-ibm-z-kvm-user-infra-installing-rhcos.adoc[leveloffset=+1]
5353

54-
include::modules/ibm-z-secure-execution.adoc[leveloffset=+2]
54+
include::modules/ibm-z-configure-encryption-kvm.adoc[leveloffset=+2]
55+
56+
include::modules/ibm-z-secure-execution.adoc[leveloffset=+3]
5557

5658
[role="_additional-resources"]
5759
.Additional resources
@@ -62,7 +64,9 @@ include::modules/ibm-z-secure-execution.adoc[leveloffset=+2]
6264

6365
* link:https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/configuring_and_managing_virtualization/securing-virtual-machines-in-rhel_configuring-and-managing-virtualization#setting-up-secure-execution-on-ibm-z_securing-virtual-machines-in-rhel[Setting up {ibm-name} Secure Execution on {ibm-z-title}]
6466

65-
include::modules/ibm-z-configure-nbde-with-static-ip.adoc[leveloffset=+2]
67+
include::modules/ibm-z-configure-hw-based-cex-encryption.adoc[leveloffset=+3]
68+
69+
include::modules/ibm-z-configure-nbde-with-static-ip.adoc[leveloffset=+3]
6670

6771
[role="_additional-resources"]
6872
.Additional resources
@@ -100,10 +104,9 @@ include::modules/cluster-telemetry.adoc[leveloffset=+1]
100104

101105
* link:https://access.redhat.com/solutions/4387261[How to generate SOSREPORT within {product-title} version 4 nodes without SSH]
102106

107+
* xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#opting-out-remote-health-reporting_opting-out-remote-health-reporting[Opting out of remote health reporting]
108+
103109
[id="next-steps_ibm-z-kvm"]
104110
== Next steps
105111

106-
* xref:../../../post_installation_configuration/cluster-tasks.adoc#available_cluster_customizations[Customize your cluster].
107-
108-
* If necessary, you can
109-
xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#opting-out-remote-health-reporting_opting-out-remote-health-reporting[opt out of remote health reporting].
112+
* xref:../../../post_installation_configuration/cluster-tasks.adoc#available_cluster_customizations[Customize your cluster]

installing/installing_ibm_z/upi/installing-ibm-z-lpar.adoc

Lines changed: 10 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,11 @@ include::modules/nw-operator-cr.adoc[leveloffset=+1]
4747

4848
include::modules/installation-user-infra-generate-k8s-manifest-ignition.adoc[leveloffset=+1]
4949

50-
include::modules/ibm-z-configure-nbde-with-static-ip.adoc[leveloffset=+1]
50+
include::modules/ibm-z-configure-boot-volume-encryption.adoc[leveloffset=+1]
51+
52+
include::modules/ibm-z-configure-hw-based-cex-encryption.adoc[leveloffset=+2]
53+
54+
include::modules/ibm-z-configure-nbde-with-static-ip.adoc[leveloffset=+2]
5155

5256
[role="_additional-resources"]
5357
.Additional resources
@@ -83,12 +87,11 @@ include::modules/cluster-telemetry.adoc[leveloffset=+1]
8387

8488
* link:https://access.redhat.com/solutions/4387261[How to generate SOSREPORT within {product-title} version 4 nodes without SSH]
8589

86-
[id="next-steps_installing-ibm-z-lpar"]
87-
== Next steps
90+
* xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#opting-out-remote-health-reporting_opting-out-remote-health-reporting[Opting out of remote health reporting]
8891

89-
* xref:../../../machine_configuration/machine-configs-configure.adoc#rhcos-enabling-multipath-day-2_machine-configs-configure[Enabling multipathing with kernel arguments on {op-system}].
92+
[id="next-steps_ibm-z-lpar"]
93+
== Next steps
9094

91-
* xref:../../../post_installation_configuration/cluster-tasks.adoc#available_cluster_customizations[Customize your cluster].
95+
* xref:../../../machine_configuration/machine-configs-configure.adoc#rhcos-enabling-multipath-day-2_machine-configs-configure[Enabling multipathing with kernel arguments on {op-system}]
9296

93-
* If necessary, you can
94-
xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#opting-out-remote-health-reporting_opting-out-remote-health-reporting[opt out of remote health reporting].
97+
* xref:../../../post_installation_configuration/cluster-tasks.adoc#available_cluster_customizations[Customize your cluster]

installing/installing_ibm_z/upi/installing-ibm-z.adoc

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,11 @@ include::modules/nw-operator-cr.adoc[leveloffset=+1]
4848

4949
include::modules/installation-user-infra-generate-k8s-manifest-ignition.adoc[leveloffset=+1]
5050

51-
include::modules/ibm-z-configure-nbde-with-static-ip.adoc[leveloffset=+1]
51+
include::modules/ibm-z-configure-boot-volume-encryption.adoc[leveloffset=+1]
52+
53+
include::modules/ibm-z-configure-hw-based-cex-encryption.adoc[leveloffset=+2]
54+
55+
include::modules/ibm-z-configure-nbde-with-static-ip.adoc[leveloffset=+2]
5256

5357
[role="_additional-resources"]
5458
.Additional resources
@@ -84,12 +88,12 @@ include::modules/cluster-telemetry.adoc[leveloffset=+1]
8488

8589
* link:https://access.redhat.com/solutions/4387261[How to generate SOSREPORT within {product-title} version 4 nodes without SSH]
8690

91+
* xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#opting-out-remote-health-reporting_opting-out-remote-health-reporting[Opting out of remote health reporting]
92+
8793
[id="next-steps_ibm-z-vm"]
8894
== Next steps
8995

90-
* xref:../../../machine_configuration/machine-configs-configure.adoc#rhcos-enabling-multipath-day-2_machine-configs-configure[Enabling multipathing with kernel arguments on {op-system}].
96+
* xref:../../../machine_configuration/machine-configs-configure.adoc#rhcos-enabling-multipath-day-2_machine-configs-configure[Enabling multipathing with kernel arguments on {op-system}]
9197

92-
* xref:../../../post_installation_configuration/cluster-tasks.adoc#available_cluster_customizations[Customize your cluster].
98+
* xref:../../../post_installation_configuration/cluster-tasks.adoc#available_cluster_customizations[Customize your cluster]
9399

94-
* If necessary, you can
95-
xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#opting-out-remote-health-reporting_opting-out-remote-health-reporting[opt out of remote health reporting].

installing/installing_ibm_z/upi/installing-restricted-networks-ibm-z-kvm.adoc

Lines changed: 12 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,9 @@ include::modules/installation-user-infra-generate-k8s-manifest-ignition.adoc[lev
5959

6060
include::modules/installation-ibm-z-kvm-user-infra-installing-rhcos.adoc[leveloffset=+1]
6161

62-
include::modules/ibm-z-secure-execution.adoc[leveloffset=+2]
62+
include::modules/ibm-z-configure-encryption-kvm.adoc[leveloffset=+2]
63+
64+
include::modules/ibm-z-secure-execution.adoc[leveloffset=+3]
6365

6466
[role="_additional-resources"]
6567
.Additional resources
@@ -70,7 +72,9 @@ include::modules/ibm-z-secure-execution.adoc[leveloffset=+2]
7072

7173
* link:https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/9/html/configuring_and_managing_virtualization/securing-virtual-machines-in-rhel_configuring-and-managing-virtualization#setting-up-secure-execution-on-ibm-z_securing-virtual-machines-in-rhel[Setting up {ibm-name} Secure Execution on {ibm-z-title}]
7274

73-
include::modules/ibm-z-configure-nbde-with-static-ip.adoc[leveloffset=+2]
75+
include::modules/ibm-z-configure-hw-based-cex-encryption.adoc[leveloffset=+3]
76+
77+
include::modules/ibm-z-configure-nbde-with-static-ip.adoc[leveloffset=+3]
7478

7579
[role="_additional-resources"]
7680
.Additional resources
@@ -106,10 +110,12 @@ include::modules/installation-complete-user-infra.adoc[leveloffset=+1]
106110

107111
* link:https://access.redhat.com/solutions/4387261[How to generate SOSREPORT within {product-title} version 4 nodes without SSH]
108112

113+
* xref:../../../openshift_images/image-configuration.adoc#images-configuration-cas_image-configuration[Image configuration resources (Classic)]
114+
115+
* xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#opting-out-remote-health-reporting_opting-out-remote-health-reporting[Opting out of remote health reporting]
116+
117+
109118
[id="next-steps_ibm-z-kvm-restricted"]
110119
== Next steps
111120

112-
* xref:../../../post_installation_configuration/cluster-tasks.adoc#available_cluster_customizations[Customize your cluster].
113-
* If the mirror registry that you used to install your cluster has a trusted CA, add it to the cluster by xref:../../../openshift_images/image-configuration.adoc#images-configuration-cas_image-configuration[configuring additional trust stores].
114-
* If necessary, you can xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#opting-out-remote-health-reporting_opting-out-remote-health-reporting[opt out of remote health reporting].
115-
* If necessary, see xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#insights-operator-register-disconnected-cluster_opting-out-remote-health-reporting[Registering your disconnected cluster]
121+
* xref:../../../post_installation_configuration/cluster-tasks.adoc#available_cluster_customizations[Customize your cluster]

installing/installing_ibm_z/upi/installing-restricted-networks-ibm-z-lpar.adoc

Lines changed: 11 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,11 @@ include::modules/nw-operator-cr.adoc[leveloffset=+1]
5555

5656
include::modules/installation-user-infra-generate-k8s-manifest-ignition.adoc[leveloffset=+1]
5757

58-
include::modules/ibm-z-configure-nbde-with-static-ip.adoc[leveloffset=+1]
58+
include::modules/ibm-z-configure-boot-volume-encryption.adoc[leveloffset=+1]
59+
60+
include::modules/ibm-z-configure-hw-based-cex-encryption.adoc[leveloffset=+2]
61+
62+
include::modules/ibm-z-configure-nbde-with-static-ip.adoc[leveloffset=+2]
5963

6064
[role="_additional-resources"]
6165
.Additional resources
@@ -89,10 +93,12 @@ include::modules/installation-complete-user-infra.adoc[leveloffset=+1]
8993

9094
* link:https://access.redhat.com/solutions/4387261[How to generate SOSREPORT within {product-title} version 4 nodes without SSH]
9195

96+
* xref:../../../openshift_images/image-configuration.adoc#images-configuration-cas_image-configuration[Image configuration resources (Classic)]
97+
98+
* xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#opting-out-remote-health-reporting_opting-out-remote-health-reporting[Opting out of remote health reporting]
99+
100+
92101
[id="next-steps_ibm-z-lpar-restricted"]
93102
== Next steps
94103

95-
* xref:../../../post_installation_configuration/cluster-tasks.adoc#available_cluster_customizations[Customize your cluster].
96-
* If the mirror registry that you used to install your cluster has a trusted CA, add it to the cluster by xref:../../../openshift_images/image-configuration.adoc#images-configuration-cas_image-configuration[configuring additional trust stores].
97-
* If necessary, you can xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#opting-out-remote-health-reporting_opting-out-remote-health-reporting[opt out of remote health reporting].
98-
* If necessary, see xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#insights-operator-register-disconnected-cluster_opting-out-remote-health-reporting[Registering your disconnected cluster]
104+
* xref:../../../post_installation_configuration/cluster-tasks.adoc#available_cluster_customizations[Customize your cluster]

installing/installing_ibm_z/upi/installing-restricted-networks-ibm-z.adoc

Lines changed: 12 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,11 @@ include::modules/nw-operator-cr.adoc[leveloffset=+1]
5656

5757
include::modules/installation-user-infra-generate-k8s-manifest-ignition.adoc[leveloffset=+1]
5858

59-
include::modules/ibm-z-configure-nbde-with-static-ip.adoc[leveloffset=+1]
59+
include::modules/ibm-z-configure-boot-volume-encryption.adoc[leveloffset=+1]
60+
61+
include::modules/ibm-z-configure-hw-based-cex-encryption.adoc[leveloffset=+2]
62+
63+
include::modules/ibm-z-configure-nbde-with-static-ip.adoc[leveloffset=+2]
6064

6165
[role="_additional-resources"]
6266
[id="additional-resources_Configure-nbde-ibm-z-restricted"]
@@ -91,10 +95,12 @@ include::modules/installation-complete-user-infra.adoc[leveloffset=+1]
9195

9296
* link:https://access.redhat.com/solutions/4387261[How to generate SOSREPORT within {product-title} version 4 nodes without SSH]
9397

94-
[id="next-steps_ibm-z-restricted"]
98+
* xref:../../../openshift_images/image-configuration.adoc#images-configuration-cas_image-configuration[Image configuration resources (Classic)]
99+
100+
* xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#opting-out-remote-health-reporting_opting-out-remote-health-reporting[Opting out of remote health reporting]
101+
102+
103+
[id="next-steps_ibm-z-zvm-restricted"]
95104
== Next steps
96105

97-
* xref:../../../post_installation_configuration/cluster-tasks.adoc#available_cluster_customizations[Customize your cluster].
98-
* If the mirror registry that you used to install your cluster has a trusted CA, add it to the cluster by xref:../../../openshift_images/image-configuration.adoc#images-configuration-cas_image-configuration[configuring additional trust stores].
99-
* If necessary, you can xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#opting-out-remote-health-reporting_opting-out-remote-health-reporting[opt out of remote health reporting].
100-
* If necessary, see xref:../../../support/remote_health_monitoring/opting-out-of-remote-health-reporting.adoc#insights-operator-register-disconnected-cluster_opting-out-remote-health-reporting[Registering your disconnected cluster]
106+
* xref:../../../post_installation_configuration/cluster-tasks.adoc#available_cluster_customizations[Customize your cluster]
Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
// Module included in the following assemblies:
2+
//
3+
// * installing/installing_ibm_z/installing-ibm-z.adoc
4+
// * installing/installing_ibm_z/installing-restricted-networks-ibm-z.adoc
5+
// * installing/installing_ibm_z/installing-ibm-z-lpar.adoc
6+
// * installing/installing_ibm_z/installing-restricted-networks-ibm-z-lpar.adoc
7+
8+
:_mod-docs-content-type: PROCEDURE
9+
[id="configuring-boot-volume-encryption-ibm-z-linuxone-environment_{context}"]
10+
= Configuring boot volume encryption in an {ibm-z-title} or {ibm-linuxone-title} environment
11+
12+
You can choose between two methods to optionally encrypt the boot volumes of your {product-title} control plane and compute nodes on {ibm-z-name} or {ibm-linuxone-name}:
13+
14+
* Linux Unified Key Setup (LUKS) encryption via {ibm-name} Crypto Express (CEX)
15+
* Network Bound Disk Encryption (NBDE)
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
// Module included in the following assemblies:
2+
//
3+
// * installing/installing_ibm_z/installing-ibm-z-kvm.adoc
4+
// * installing/installing_ibm_z/installing-restricted-networks-ibm-z-kvm.adoc
5+
6+
:_mod-docs-content-type: PROCEDURE
7+
[id="configuring-encryption-kvm-ibm-z-linuxone-environment_{context}"]
8+
= Configuring encryption for nodes in an {ibm-z-title} or {ibm-linuxone-title} environment
9+
10+
You can choose between three methods to optionally secure your {product-title} control plane and compute nodes on {ibm-z-name} or {ibm-linuxone-name}:
11+
12+
* {ibm-name} Secure Execution
13+
* Linux Unified Key Setup (LUKS) encryption via {ibm-name} Crypto Express (CEX)
14+
* Network Bound Disk Encryption (NBDE)

0 commit comments

Comments
 (0)