Oxide's key-hierarchy strategy for rack-level security

Has anybody seen my keys? A key-hierarchy strategy for rack-level security

Oxide's RFD 301 details a key-hierarchy strategy for rack-level security. It starts with a rack secret, split into shares distributed across sleds, which can only be reconstructed with enough shares. From this secret, keys are derived or wrapped to protect data at rest on U.2 drives using ZFS encryption. The design ensures that stealing a subset of drives or sleds yields no useful data, and supports key rotation to mitigate compromise.

An attacker would have to steal at least K of these drives to reconstruct the rack secret, which is infeasible without significant time and disruption during physical access.

More from this day

2026-09-07