Idea: - Setup HSM based encryption - Randomly create secret key ( you might also need to update the hsmdaemon.toml file accordingly ) Advantage: It would help the deployments easy. Reference/Origin of this idea -> https://github.com/owncloud/encryption/pull/90#discussion_r255472939