...
- Start distributed process CACHE_GROUP_KEY_CHANGE_PREPARE, each node
- verifies that re-encryption is not in progress for the specified cache group.
- ensures that new key identifier does not exist
- After successful completion of PREPARE, start distributed process CACHE_GROUP_KEY_CHANGE_FINISH, each node
- saves logical WAL record (ENCRYPTION_STATUS_RECORD) with current groups and key identifiers to start re-encryption after logical recovery.
- save the new key in the metastore (as inactive key)
- sets it for writing
- adds the mapping "WAL segment -> *old* key identifier" (to safely cleanup previous key in the future)
- save current keys and WALl mappings into the metastore.
- starts background re-encryption of an existing data.
...
{"serverDuration": 155, "requestCorrelationId": "6b1f9cb3990a7231"}