Hi Team,
We are currently evaluating Proxmox VE 9.2.3 for an Airport Edge use case and have a requirement for storage encryption at rest.
We understand that ZFS provides native encryption functionality, which is currently documented as an experimental phase. Before proceeding further with our evaluation, we would like to clarify the following:
1. Is native ZFS encryption at rest fully supported in Proxmox VE 9.2.3 for production environments?
2. Since ZFS encryption is documented as an experimental feature:
- What is the current support status of this functionality?
- Is there a planned timeline for making ZFS encryption fully production-ready?
3. If ZFS encryption is used in an HA environment:
- How are the encryption keys managed?
- How is the encryption key made available when a VM is migrated or failed over to another Proxmox node?
- Are there any limitations or recommended practices for key management in an HA configuration?
4. If native ZFS encryption is not currently recommended or supported for production HA deployments, what encryption-at-rest solution does Proxmox recommend for this use case?
5. Is there any beta/preview implementation or upcoming release that provides production-ready storage encryption at rest that we could evaluate?
Our primary requirement is encryption of data at rest, including VM and storage data, while maintaining supportability in an HA environment.
Could you please confirm the current supported approach and recommended architecture for this requirement?
We are currently evaluating Proxmox VE 9.2.3 for an Airport Edge use case and have a requirement for storage encryption at rest.
We understand that ZFS provides native encryption functionality, which is currently documented as an experimental phase. Before proceeding further with our evaluation, we would like to clarify the following:
1. Is native ZFS encryption at rest fully supported in Proxmox VE 9.2.3 for production environments?
2. Since ZFS encryption is documented as an experimental feature:
- What is the current support status of this functionality?
- Is there a planned timeline for making ZFS encryption fully production-ready?
3. If ZFS encryption is used in an HA environment:
- How are the encryption keys managed?
- How is the encryption key made available when a VM is migrated or failed over to another Proxmox node?
- Are there any limitations or recommended practices for key management in an HA configuration?
4. If native ZFS encryption is not currently recommended or supported for production HA deployments, what encryption-at-rest solution does Proxmox recommend for this use case?
5. Is there any beta/preview implementation or upcoming release that provides production-ready storage encryption at rest that we could evaluate?
Our primary requirement is encryption of data at rest, including VM and storage data, while maintaining supportability in an HA environment.
Could you please confirm the current supported approach and recommended architecture for this requirement?