Boot disk encryption
Stay organized with collections
Save and categorize content based on your preferences.
Google Distributed Cloud (GDC) air-gapped appliance uses Linux Unified Key Setup (LUKS) based disk
encryption with YubiKeys.
For each GDC air-gapped appliance, three or more YubiKeys are shipped separately
to the customer. The YubiKeys are FIPS 140-2 certified. For more information on the YubiKey model, see
https://www.yubico.com/product/yubikey-5-nano-fips/.
The USB ports on each server blade of the device are enabled with USB dongles.
The YubiKeys are inserted into the server machines as part of the device setup.
Each YubiKey is bound to a blade during the bootstrap process and cannot be
used with another blade. The keys cannot be used interchangeably.
The YubiKey only needs to be inserted during the boot process. If you remove
the YubiKey after the boot process, it doesn't affect the operation of the
appliance. If you remove the YubiKey, it must be reinserted in the same node
before the next boot. Ensure that the YubiKeys are transferred separately
from the appliance to protect against server theft.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-09-17 UTC."],[],[]]