Skip to content

Conversation

@rmvangun
Copy link
Contributor

@rmvangun rmvangun commented Dec 8, 2025

Makes disk encryption optional on the cluster. It is enabled by default, but it is desirable to disable it when data isn't sensitive or reducing costs.

Signed-off-by: Ryan VanGundy 85766511+rmvangun@users.noreply.github.com

* Enable oidc issuer and workload identity
* Use system-assigned managed identities
* Add required disk manager role (breaks cluster otherwise)

Signed-off-by: Ryan VanGundy <85766511+rmvangun@users.noreply.github.com>
Signed-off-by: Ryan VanGundy <85766511+rmvangun@users.noreply.github.com>
Makes disk encryption optional on the cluster. It is enabled by default, but it is desirable to disable it when data isn't sensitive or reducing costs.

Signed-off-by: Ryan VanGundy <85766511+rmvangun@users.noreply.github.com>
Base automatically changed from feat/kubelet-oidc-roles to main December 8, 2025 19:17
Signed-off-by: Ryan VanGundy <85766511+rmvangun@users.noreply.github.com>
Signed-off-by: Ryan VanGundy <85766511+rmvangun@users.noreply.github.com>
@rmvangun rmvangun merged commit 05edcaf into main Dec 9, 2025
7 checks passed
@rmvangun rmvangun deleted the feat/aks-optional-disk-encryption branch December 9, 2025 14:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants