Review the enabled state of an Alicloud KMS key

Check the state of keys that protect data still in use.

Description

A disabled KMS key cannot perform encryption or decryption. Disks and applications that depend on the key can be affected by changes to its state.

Potential impact

Disabling a key still in use may interrupt data access or service operation.

Remediation

Keep required keys at status = "Enabled". Confirm the reason before re-enabling a key disabled for incident response or retirement.

Examples

The examples change the key state from Disabled to Enabled. Do not apply this blindly to keys being retired or contained after compromise.

Before

hcl
resource "alicloud_kms_key" "key" {
  description            = "Hello KMS"
  pending_window_in_days = "7"
  status                 = "Disabled"
}

After

hcl
resource "alicloud_kms_key" "key" {
  description            = "Hello KMS"
  pending_window_in_days = "7"
  status                 = "Enabled"
}

References