Learn to enable Docker Swarm’s Auto-Lock feature for encrypting Raft logs and securing cluster management with an unlock key.
In this walkthrough, you’ll learn how to enable Docker Swarm’s Auto-Lock feature to encrypt Raft logs and TLS keys on disk. With Auto-Lock enabled, any manager restarting or rejoining the cluster must provide the unlock key—adding a robust layer of security.
Even with Auto-Lock active, manager1 can query node status without unlocking:
Copy
Ask AI
[root@manager1 ~]# docker node lsID HOSTNAME STATUS AVAILABILITY MANAGER STATUS ENGINE VERSIONkvbht486wmj881wp5vqxp53 * manager1 Ready Active Leader 19.03.8u8imabedhzsu4cawtoz6jh32 manager3 Ready Active Reachable 19.03.8s2ymqdbtfal661imydx31rlno manager2 Ready Active Reachable 19.03.838oehhk79ss5rk2coejcavha worker1 Ready Active 19.03.8k4gc50oc0n8k6jm3f6bm2bph worker3 Ready Active 19.03.81pqddmh2fcoy79vq9najr841d worker2 Ready Active 19.03.8