Concepts¶
The three ideas sceau is built from, each with its own page:
-
The gRPC contract between kube-apiserver and sceau:
Status,Encrypt,Decrypt, the DEK lifecycle, and howkey_iddrives rotation and migration. -
The TPM 2.0 object model: the deterministic RSA-2048 SRK primary,
fixedTpm+fixedParentsealed-data objects, and the envelope byte format that becomes the KMS ciphertext. -
What TPM sealing actually protects against, the explicit "TPM loss = data loss" trade-off, and the PCR-binding roadmap.
If you want the 10,000-foot view of how these compose, read the Overview first. For the formal architecture model, see Architecture.