CockroachDB是否支持数据库级加密?多客户端DB密钥隔离方案咨询
Great question—let’s break this down into your two core concerns clearly:
1. Can CockroachDB implement database-level encryption?
Short answer: No, not natively at the storage level.
CockroachDB’s built-in Encryption at Rest operates at the cluster-wide level. This means all data across the entire cluster (all databases, tables, and rows) is encrypted using a single root encryption key (managed either locally or via a KMS like AWS KMS, GCP Cloud KMS, etc.). There’s no out-of-the-box way to assign unique storage-level encryption keys to individual databases within the same cluster.
That said, if you need per-database encryption controls, you have a couple of practical workarounds:
- Column-level encryption: CockroachDB supports native column-level encryption, where you can encrypt specific columns with unique keys. You could use distinct keys for columns across different databases to achieve a form of per-database encryption (though this is at the data layer, not the storage layer).
- Application-layer encryption: Encrypt sensitive data before writing it to the database. This lets you manage separate encryption keys for each client database entirely outside of CockroachDB.
2. Can each database in the same cluster use independent storage volumes with different keys?
Again, no—this isn’t possible with CockroachDB’s architecture.
CockroachDB uses a distributed, sharded storage model where data is split into ranges (64MB chunks). These ranges are automatically replicated and distributed across nodes in the cluster, and a single range can contain data from multiple databases. There’s no mechanism to pin an entire database to a dedicated storage volume, let alone assign a unique encryption key to that volume.
The cluster’s storage is treated as a unified pool; you can’t partition storage resources or encryption keys per database.
Alternative for strict isolation
If you absolutely need storage-level encryption isolation per client database, your best bet is to deploy separate CockroachDB clusters for each client. Each cluster can then use its own dedicated storage volumes and unique encryption keys, giving you the full isolation you’re looking for.
内容的提问来源于stack exchange,提问作者Mike

