# Encryption at rest/in transit

**URL:** <https://discuss.kubernetes.io/t/encryption-at-rest-in-transit/9433>\
**Category:** General Discussions\
**Created:** [January 23, 2020, 5:23pm UTC](https://discuss.kubernetes.io/t/encryption-at-rest-in-transit/9433 "2020-01-23T17:23:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![grace\_k](https://avatars.discourse-cdn.com/v4/letter/g/cab0a1/32.png) [@grace\_k](https://discuss.kubernetes.io/u/grace_k)\
**Post date:** [January 23, 2020, 5:23pm UTC](https://discuss.kubernetes.io/t/encryption-at-rest-in-transit/9433/1 "2020-01-23T17:23:21Z")

</div>

How does Kubernetes secure data at rest and data in transit?

---

<div class="post-metadata">

**Author:** ![johnharris85](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/johnharris85/32/1502_2.png) [@johnharris85](https://discuss.kubernetes.io/u/johnharris85)\
**Post date:** [February 4, 2020, 8:19pm UTC](https://discuss.kubernetes.io/t/encryption-at-rest-in-transit/9433/2 "2020-02-04T20:19:28Z")

</div>

For details on encrypting at rest take a look at [Encrypting Secret Data at Rest - Kubernetes](https://kubernetes.io/docs/tasks/administer-cluster/encrypt-data/). In transit, the control plane components all talk to each other via TLS using certs signed by the Kubernetes CA.

Transit encryption of user workloads is an exercise for the user and can be achieved by configuring the workloads to use a secure protocol if desired.
