...
- Check that all baseline nodes online.
- Start distributed process GROUP_KEY_CHANGE_PREPARE, each node
- verifies that re-encryption not in progress (?)
- ensures that new key identifier does not exists
- adds new key
- After successful completion of PREPARE, start distributed process GROUP_KEY_CHANGE_FINISH, each node
- sets new key for writing
- adds the mapping "WAL segment -> *old* key identifier" (to safely cleanup this key in the future)
- stores current pages count as total pages for background re-encryption (on applicable partitions).
- starts background re-encryption
...
{"serverDuration": 164, "requestCorrelationId": "f0638ad115eaac43"}