Skip to content

Conversation

@christinaausley
Copy link
Contributor

Description

Closes https://github.com/camunda/product-hub/issues/3285.

Adds new BYOK failure-mode documentation

This PR introduces a new page describing how Camunda 8 SaaS behaves when an external Amazon KMS encryption key (BYOK) becomes unavailable. It covers scenarios such as keys being disabled, scheduled for deletion, deleted, or misconfigured.

What’s included

  • Expected behavior during cluster startup and runtime
  • Effects on orchestration operations, backups, and reads/writes to encrypted storage
  • Behavior of pause and resume actions when the key is unavailable
  • Recovery expectations when a key is re-enabled
  • Permanent data-loss scenarios when a key is deleted
  • Operational guidance and recommendations
  • Cross-links added from the BYOK overview, setup guide, FAQ, and key rotation pages

Why this is needed

Customers using external encryption keys require clear expectations on failure modes, operational safeguards, and troubleshooting. Previous documentation did not explain how the system behaves when the key becomes inaccessible.

Follow-up

  • Engineering validation is complete based on the Slack discussion
  • Future UI and Console improvements to key-related error surfacing may require updates

When should this change go live?

  • This is a bug fix, security concern, or something that needs urgent release support. (add bug or support label)
  • This is already available but undocumented and should be released within a week. (add available & undocumented label)
  • This is on a specific schedule and the assignee will coordinate a release with the Documentation team. (create draft PR and/or add hold label)
  • This is part of a scheduled alpha or minor. (add alpha or minor label)
  • There is no urgency with this change (add low prio label)

PR Checklist

  • My changes are for an upcoming minor release and are in the /docs directory (version 8.9).
  • My changes are for an already released minor and are in a /versioned_docs directory.

@christinaausley christinaausley self-assigned this Dec 9, 2025
@christinaausley christinaausley added component:docs Documentation improvements, including new or updated content deploy Stand up a temporary docs site with this PR labels Dec 9, 2025
@github-actions github-actions bot temporarily deployed to camunda-docs December 9, 2025 16:56 Destroyed
@christinaausley
Copy link
Contributor Author

Hi @hilalbursalii @stathis-cmnd this is ready for your final review 😄

@github-actions github-actions bot temporarily deployed to camunda-docs January 7, 2026 18:23 Destroyed
Copy link

@psetzer-camunda psetzer-camunda left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No additions at this stage.

@christinaausley christinaausley merged commit 8b5dbba into main Jan 16, 2026
7 checks passed
@christinaausley christinaausley deleted the 3285-byok-behavior branch January 16, 2026 18:54
@github-actions
Copy link
Contributor

🧹 Preview environment for this PR has been torn down.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

component:docs Documentation improvements, including new or updated content deploy Stand up a temporary docs site with this PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants