Skip to content

Persist Data Protection keys to Azure Blob Storage or Redis - #168

Merged
woksin merged 9 commits into
mainfrom
feat/shared-data-protection-keys
Oct 1, 2026
Merged

woksin merged 9 commits into
mainfrom
feat/shared-data-protection-keys

Conversation

@woksin

@woksin woksin commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Replicas can now share one Data Protection key ring through Azure Blob Storage or Redis instead of a mounted volume, so sessions and tokens survive restarts and load balancing on platforms without shared persistent disks.

Added

Changed

…ly encrypted with Azure Key Vault

Add a DataProtection configuration section selecting the key store (file system by default, Azure Blob Storage or Redis) and an optional Key Vault key that protects the key ring at rest. Contradictory or incomplete settings fail at startup.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant