Overview
If encryption was not enabled at installation, you can enable internal encryption (encryption with internal key management). After enabling internal encryption, you can switch from internal encryption to an EKM.
If internal encryption was enabled at installation, you can switch from internal encryption to an EKM.
You cannot switch between EKM types.
When encryption is enabled on the cluster, every tenant created on the cluster must be associated with an encryption group. This can be a new or a pre-existing encryption group.