December 14, 2017 By Jeff Sloyer 2 min read

Encrypted Workers in the IBM Cloud Container Service

The IBM Cloud Container Service combines Docker and Kubernetes to deliver powerful tools, an intuitive user experiences, and built-in security and isolation. You can rapidly deliver your apps while leveraging IBM Cloud services like artificial intelligence with Watson.

Today, we are proud to announce that we are turning on encryption of worker nodes by default. Many internal teams and external customers asked us for encrypted data volumes on worker nodes, and we listened to you!

What this means for you

As of today, this change makes your data in new clusters and workers that you create even more secure by default.

IBM Cloud Container Service provides encrypted data partitions for all worker nodes by provisioning them with two local SSD partitions. The first boot partition is not encrypted, and the second partition mounted to /var/lib/docker is unlocked at boot time by using LUKS encryption keys. Each worker in each Kubernetes cluster has its own unique LUKS encryption key, managed by the IBM Cloud Container Service. At boot time, they are pulled securely and then discarded after the encrypted disk is unlocked.

You might find that some workloads with high-performance disk I/O requirements are impacted when encrypted. In some of our encrypted performance tests, we saw single-digit percentage disk I/O impact, but in most there was no impact. If you have performance-sensitive workloads, you might want to do benchmarks tests with both encryption-enabled and disabled to help you decide if you want to turn off encryption.

How to get started

From the IBM Cloud console GUI, encryption is already turned on for you. If you want to turn off encryption, clear the Encrypt local disk check box (see below) when you create a cluster or add a worker to an existing cluster.

From the CLI, to take advantage of default encryption, first update your plug-in with the following command:

bx plugin update container-service -r Bluemix

Now, encryption is turned on by default when you create a cluster or add a worker to an existing cluster! If you want to disable encryption, specify the --disable-disk-encrypt option when using the cluster-create or the worker-add commands.

Questions or comments?

Please join us on our public Slack channel at

More from

How the IBM watsonx platform breaks down barriers to generative AI adoption

5 min read - As businesses explore the potential of generative AI, they’re also at an increased risk of complications from complex data environments, a limited number of workers with AI skills and AI governance frameworks that holistically consider all compliance requirements (such as internal policies and procedures, industry standards like NIST AI and regulations). Although these challenges are similar to those of past AI technologies, generative AI demands even more specialized skills, including management of large, diverse data sets and the ability to…

AI in sports: Changing the game for fans and players alike

4 min read - At this year’s US Open tennis tournament, IBM’s AI-powered features bring fans even closer to the action. It turns out that sports and AI make for a pretty good match—and AI may even prove to be a game-changer for the sports industry. For the US Open, IBM delivers AI-generated summaries for every men's and women’s singles match. And for the second year, IBM is providing an enhanced version of AI commentaries with automated English-language audio and subtitles using watsonx. The…

Apache Flink for all: Making Flink consumable across all areas of your business

3 min read - In an era of rapid technological advancements, responding quickly to changes is crucial. Event-driven businesses across all industries thrive on real-time data, enabling companies to act on events as they happen rather than after the fact. These agile businesses recognize needs, fulfill them and secure a leading market position by delighting customers. This is where Apache Flink shines, offering a powerful solution to harness the full potential of an event-driven business model through efficient computing and processing capabilities. Flink jobs,…

IBM Newsletters

Get our newsletters and topic updates that deliver the latest thought leadership and insights on emerging trends.
Subscribe now More newsletters