Your experience from a KMS angle will be especially valuable to validate the new KMS interface, thanks for offering to take a look.
> (I suppose HDFS at reset encryption is not considered for whatever reason) We don't use HDFS directly so our focus right now is HBase only. I do not have much insight into how HDFS manages encryption, but I believe the HBase encryption was originally derived from it, so it may not be too different. However, the majority of my changes are around the service and persistence, which won't have any equivalence in HDFS. PS: My previous reply seems to have gotten lost, so trying again. On 2025/11/10 19:40:28 Wei-Chiu Chuang wrote: > Hi, I'd like to check it out later. > > I used to maintain Hadoop KMS for HDFS and Ozone. It tooks us many years to > stabilize and improve scale/performance, so a lot of lessons learned along > the way. > (I suppose HDFS at reset encryption is not considered for whatever reason) >
