3 ms·
The most wrong part of that previous team is to store private keys unencrypted in the cloud, not the performance part.
by netheril96 3y ago
The most wrong part of that previous team is to store private keys unencrypted in the cloud, not the performance part.
- thraxil 3y agoI mean... literally every VM running nginx or apache that I've ever seen has had the SSL certs just sitting on the filesystem in /etc/ssl or /etc/letsencrypt or similar... All of letsencrypt's documentation points people in that direction.
- oittaa 3y agoMy understanding is that everything is encrypted by default in GCP. Though you need to manually configure encryption keys if you want to prevent Google ever having access to your data.
- FooBarWidget 3y agoThis I don't understand. Even if you configure KMS, those are still keys stored on Google infra.
- oittaa 3y agoYou can use your own KMS outside the Google infrastructure. https://cloud.google.com/storage/docs/encryption/customer-supplied-keys https://cloud.google.com/storage/docs/encryption/customer-su...