TECHNICAL GUIDE
Fabrics & Scaling · FAB-07

Encrypt & Decrypt VM Storage

Encrypt and decrypt VM storage from Storage Fabric.

STORAGE SECURITY

Encrypt or decrypt VM storage

Modern infrastructure protection has to cover more than a host firewall. Sovereign Data requirements increasingly ask where data is stored, who can access it, and what remains exposed when compute moves to another site or cloud. Moving a workload to remote infrastructure can expand the trust boundary to the platform that hosts it; STRATUM storage encryption keeps the VM disk image protected at rest.

For a broader sovereign-data posture, STRATUM can also protect the VM runtime in memory where Encrypted Runtime is enabled and supported, while the always-on encrypted Continuum protects data in motion. That gives the operator controls across data at rest, data in use, and data in motion. Start an encrypt or decrypt action only when the image is in the required state for conversion, and let the conversion finish before starting dependent workloads.

PROTECT THE WORKLOAD. NOT JUST THE DISK.

Storage encryption protects the VM image at rest. Encrypted Runtime can protect the running workload in memory. The Continuum protects traffic in motion.

PROCEDURE

Procedure

STEP 01

Storage Fabric Encrypt Action

Select the VM image and choose Encrypt from Storage Fabric when the image is eligible for conversion.

FIGURE 01Storage Fabric Encrypt Action
STEP 02

Confirm Storage Encryption

Review the image named in the confirmation dialog and approve the encryption operation only when it is the intended target.

FIGURE 02Confirm Storage Encryption
STEP 03

Storage Fabric Decrypt Action

Choose Decrypt on an encrypted VM image when the storage must be returned to an unencrypted state.

FIGURE 03Storage Fabric Decrypt Action
STEP 04

Confirm Storage Decryption

Confirm the decrypt operation for the selected image and allow the conversion to finish before starting dependent workloads.

FIGURE 04Confirm Storage Decryption
RESULT

The outcome you should see

The selected VM image reports the requested encrypted or decrypted state after conversion completes.