Built into vCenter, this provider generates encryption keys itself, so no external KMS is needed; back it up before first use.
Read more: Broadcom TechDocs
In the Ultra Transcenders books
Each book explains vSphere Native Key Provider in context, with comparison tables and the common traps.
Terms in this definition
- vCenter
Management software for VMs, clusters and ESX hosts. Each domain in VCF gets a dedicated one.
- Provider
The organisation that shares data in OpenSharing. Recipients also see a provider as a Unity Catalog securable, from which shares can be mounted as catalogs.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- External
API Management virtual network mode in which the gateway stays public but can call private back ends inside the VNet.
- KMS
Legacy AKS plug-in using an Azure Key Vault key to encrypt Kubernetes Secrets at rest in etcd. On Kubernetes 1.33 onwards, Microsoft Learn points to the newer KMS data encryption experience instead.
- FIRST
A DAX function available only inside visual calculations. It fetches the value at the start of one axis of the visual's matrix, which makes it handy for comparing each point with the first; its opposite is LAST.
Related terms
- KDK
A key created by vCenter for a vSphere Native Key Provider and distributed to the hosts in a cluster. Each host uses it to derive encryption keys locally, so no external key server has to supply KEKs.
- KMIP
An industry-standard protocol through which a client application talks to a key management server. vCenter acts as a KMIP client for a standard key provider, whereas vSphere Native Key Provider does not need a KMIP server at all.
- KMS
A KMIP-compliant key server, separate from vCenter, that provides KEKs through a standard key provider. When vSphere Native Key Provider is used, no such server is required.