The KMIP cluster goes fully dark for a scheduled two-hour maintenance window on Friday night, while an appliance under external key management is mid-stream carrying live backup traffic. What is the realistic expectation for those two hours?
Select an answer to reveal the explanation.
Short Explanation
Here's the nuance people get wrong: the door is already open. A running system has its keys cached, so traffic rides that cache for a while - but don't mistake 'keeps running' for 'is safe': one reboot during the window and you're locked out until the vault returns. Redundant, reachable key managers are what turn this from a gamble into a schedule.
Full Explanation
After a successful unlock, the key material needed for data I/O resides in the system's working memory, so reads and writes do not round-trip to the KMS per operation, and a brief outage does not interrupt a system that is already up. During the outage, unlocks and key-management operations fail - so the danger is any event that takes the system down and back up inside the window. External KMS designs mandate multiple reachable servers for exactly this reason; a blackout makes a theoretical dependency live. Per-block KMS round trips would make sustained throughput impossible and misunderstand the hierarchy: data keys are unwrapped into memory at unlock, not negotiated per block. Automatic fallback to a local master key is invented behavior - on an externally managed system no local copy exists, by design and policy, which is what makes the standard worth implementing. Keys being permanent ignores the unlock model: after a restart the system re-acquires keys from the manager, and a dark cluster then means a system that cannot come back up. Exam caveat: cached tolerance is not an invitation to schedule KMS downtime casually - confirm vendor guidance and ensure no reboot or failover can coincide with the window. Operational check: during a planned failover test, verify the appliance remains unlocked and a standby server answers retrieval, and document the unlock procedure for a system that goes down mid-window.