3 comments
Oxide's trust quorum approach is also discussed on this podcast episode:<p><a href="https://oxide-and-friends.transistor.fm/episodes/building-a-quorum-of-trust-in-the-oxide-rack" rel="nofollow">https://oxide-and-friends.transistor.fm/episodes/building-a-...</a>
Is there any concern in this scheme with losing access to storage either temporarily or permanently due to losing access to key shares?
The bit I liked most is wrapping the old rack secret under a key derived from the new epoch so prepare can hand out shares without unlocking until commit<p>That tension between needing both secrets for ZFS rekey and only serving shares for the committed epoch is a real distributed systems headache and this is a clean way out of it