Verify the cluster's ability to perform data encryption. Create a test secret:
kubectl create secret generic kubernetes-the-hard-way --from-literal="mykey=mydata"
Log in to one of your controller servers, and get the raw data for the test secret from etcd:
sudo ETCDCTL_API=3 etcdctl get \