One of the key topics we covered as part of our Fast Start education was encryption at rest for VMware on the IBM Cloud. There are many options for encrypting your workloads at rest, including:
- VMware vSAN encryption
- VMware vSphere encryption
- HyTrust Data Control, part of IBM Cloud Secure Virtualization
- Any other existing encryption solution you wish to bring to IBM Cloud
The first three offerings are available today directly from IBM Cloud for VMware Solutions, although some assembly is required in each case. There are important tradeoffs between these options that you need to take into consideration, such as ease of use, interoperability with other solutions like workload migration tooling, and the nature of what is encrypted. The following table that I shared at Fast Start summarizes the differences between these solutions:
Comparison | vSAN encryption | vSphere encryption | HyTrust Data Control |
---|---|---|---|
Encryption type | Datastore disks encrypted @ hypervisor
Secures: disk drives |
VM disks encrypted @ hypervisor
Secures: VMDK files, disk traffic en route to datastore |
Agent-based encryption of disks within VM
Secures: VMDK files, disk traffic en route to datastore |
Key management | External KMS must be provided (not included) supporting KMIP 1.1 (e.g., IBM KMIP for VMware, IBM SKLM, or HyTrust Key Control) | External KMS must be provided (not included) supporting KMIP 1.1 (e.g., IBM KMIP for VMware, IBM SKLM, or HyTrust Key Control) | HyTrust Key Control (included) |
Additional capabilities | Together with HyTrust Cloud Control, provides advanced access control, auditing, approval, and compliance capabilities; and enables Boundary Control for geofencing and hardware trust | ||
Cost |
|
Key management server |
|
Limitations |
|
Eliminates benefit of vSAN deduplication and compression | Eliminates benefit of vSAN deduplication and compression |
Migration | Compatible with all migration technologies |
|
Compatible with all migration technologies provided that HyTrust key management server availability and host compliance (if applicable) are maintained across sites. Some extra recovery steps are required post migration if the workload IP addressing has changed. |
One thought on “Encryption at rest for VMware on IBM Cloud”