Skip to content

feat: enable Customer-Managed Encryption Keys (CMEK) for Slurm GCP - #107

Draft
cboneti wants to merge 1 commit into
developfrom
feature/slurm-kms-encryption
Draft

cboneti wants to merge 1 commit into
developfrom
feature/slurm-kms-encryption

Conversation

@cboneti

@cboneti cboneti commented Mar 24, 2026

Copy link
Copy Markdown
Owner
  • Plumb KMS variables (disk_encryption_key, etc.) down from nodeset/login modules through instance_template wrappers.
  • Inject kms_key_self_link explicitly in the boot_disk override of google_compute_instance_from_template.
  • Add slurm_bucket_kms_key to the controller module to encrypt the generated Slurm configuration bucket.
  • Patch util.py to handle missing md5_hashes from CMEK-encrypted GCS configuration blobs by falling back to crc32c.

Submission Checklist

NOTE: Community submissions can take up to 2 weeks to be reviewed.

Please take the following actions before submitting this pull request.

  • Fork your PR branch from the Toolkit "develop" branch (not main)
  • Test all changes with pre-commit in a local branch #
  • Confirm that "make tests" passes all tests
  • Add or modify unit tests to cover code changes
  • Ensure that unit test coverage remains above 80%
  • Update all applicable documentation
  • Follow Cluster Toolkit Contribution guidelines #
- Plumb KMS variables (disk_encryption_key, etc.) down from nodeset/login modules through instance_template wrappers.
- Inject kms_key_self_link explicitly in the boot_disk override of google_compute_instance_from_template.
- Add slurm_bucket_kms_key to the controller module to encrypt the generated Slurm configuration bucket.
- Patch util.py to handle missing md5_hashes from CMEK-encrypted GCS configuration blobs by falling back to crc32c.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

1 participant