---
title: "Fortanix DSM for Encrypting Kubernetes Secrets Stored in etcd"
slug: "fortanix-dsm-for-encrypting-kubernetes-secrets-stored-in-etcd"
updated: 2026-04-01T08:28:44Z
published: 2025-10-24T07:02:41Z
canonical: "support.fortanix.com/fortanix-dsm-for-encrypting-kubernetes-secrets-stored-in-etcd"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.fortanix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Fortanix DSM for Encrypting Kubernetes Secrets Stored in etcd

Effective Kubernetes 1.10, a new feature called ***KMS Encryption Provider*** lets organizations bring their own KMS (ideally an integrated HSM).

*For more information on how to encrypt Kubernetes secrets with Key(s) stored in* ***Fortanix-Data-Security-Manager (DSM)****, refer to* [*Kubernetes KMS Plugin for Fortanix Data Security Manager*](https://github.com/fortanix/k8s-sdkms-plugin/blob/master/README.md)*.*

Fortanix Data Security Manager (DSM) is the world’s first cloud service secured with Intel® SGX. With Fortanix DSM, you can securely generate, store, and use cryptographic keys and certificates, as well as other secrets such as passwords, API keys, tokens, or any blob of data. Your business-critical applications and containers can integrate with Fortanix DSM using legacy cryptographic interfaces (PKCS#11, CNG, and JCE) or using the native Fortanix DSM RESTful interface.

## Related

- [Amazon Elastic Kubernetes Service with Fortanix Confidential Computing Manager](/amazon-elastic-kubernetes-service-with-fortanix-ccm.md)
- [Fortanix DSM with Ansible Lookup Plugin](/fortanix-dsm-with-ansible-lookup-plugin.md)
- [Microsoft CNG Key Storage Provider](/fortanix-dsm-clients-microsoft-cng-key-storage-provider.md)
