Insert the YubiKeys into the device

This page describes how to verify and insert the YubiKeys into Google Distributed Cloud (GDC) air-gapped appliance.

Before you begin

Verify cabling

Verify YubiKeys are present

Each GDC air-gapped appliance is shipped with YubiKeys in the original packaging. If the YubiKeys arrive opened (or in damaged packaging), open a support case immediately.

Insert the YubiKeys

To authenticate blades and decrypt local storage during startup, you must insert a dedicated YubiKey into each server prior to booting.

Complete the following steps to install and handle the YubiKeys:

  1. Unpack each YubiKey and insert it into a server USB port.
    • Make sure the gold contact pins faces upward.
    • Insert one YubiKey per server across all three servers. If a YubiKey is missing at startup, the operating system fails to boot and displays a console error.
  2. Start the bootstrap process. During bootstrapping, the system binds each YubiKey to its specific blade. After binding, keys are node-specific and can't be used interchangeably.
  3. (Optional) Remove the YubiKeys after the appliance finishes booting: removing a YubiKey after boot won't disrupt active appliance operations.
  4. Reinsert the corresponding YubiKey into its original node before the next reboot. Each blade requires its specific bound YubiKey to decrypt and boot successfully.

For detailed hardware specifications, see the YubiKey 5 Nano FIPS product overview: https://www.yubico.com/product/yubikey-5-nano-fips/

What's next

Connect the laptop to the switch