Skip to content

K8s node/enclave migration #6683

Answered by achamayou
bsenthilr asked this question in Q&A
Dec 4, 2024 · 1 comments · 3 replies
Discussion options

You must be logged in to vote

CCF does not currently seal any data with enclave-specific keys. The only thing that is sealed is the ledger secrets, and that's done with a wrapper key shared across members. More detail can be found on this page.

It is possible to automate disaster recovery, but note that on each DR restart, the service has a new service identity. Clients need to be able to cope with that, and should bootstrap trust in the service again.
Clients also need to be aware that the new service may have started from a truncated ledger and rolled back some of their transactions. They can use the receipts they have previously obtained to confirm whether that's the case.

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@bsenthilr
Comment options

@achamayou
Comment options

Answer selected by bsenthilr
@bsenthilr
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants