Starting with Percona XtraDB Cluster (PXC) 8.0, replication
traffic encryption is enabled by default. That said, it’s common
to find clusters running without TLS that suddenly need it: a new
compliance requirement, an audit finding, a network segment that
is no longer considered trusted.
PXC has a variable for exactly that case,
pxc-encrypt-cluster-traffic, which handles SSL encryption for
inter-node traffic, including State Snapshot Transfer (SST),
Incremental State Transfer (IST), and the group communication the
nodes use for replication.
The variable is not dynamic, and turning it on normally costs a
full cluster restart since the node that encrypts traffic listens
on ssl:// while its peers are still on tcp://. If a node joins
the cluster with TLS enabled while remaining nodes don’t, the
restarting node fails to reach out to the other peers with the
following error:
2026-09-02T02:16:02.359992Z 0 [Note] [MY-000000] …
[Read more]