At-rest-encryption may be required for some applications security policies. Encrypted shared data stores already exist, but there is currently no node-local encryption for volumes such as ephemeral volumes that could potentially store temporary sensitive data.
A CSI driver may be able to close this gap. Alternatively, the entire nodes filesystem could be encrypted at a performance penalty.
https://kubernetes.io/docs/concepts/storage/ephemeral-volumes/#csi-ephemeral-volumes