{"id":"hcp-etcd-encryption-secretencryption-field","text":"In HCP, etcd encryption is configured via the `SecretEncryption` field on the `HostedCluster` resource (supporting AES-CBC or KMS for AWS), unlike standalone OCP which uses the `APIServer` resource.","truth_value":"IN","source":"entries/2026/03/05/en-documentation-openshift_container_platform-417-html-hosted_control_planes-hos.md","source_url":"","source_hash":"c2700904fc61dac6","justifications":[],"dependents":[],"metadata":{},"explanation":{"steps":[{"node":"hcp-etcd-encryption-secretencryption-field","truth_value":"IN","reason":"premise"}]}}