Description
A disabled KMS key cannot perform encryption or decryption. Disks and applications that depend on the key can be affected by changes to its state.
Potential impact
Disabling a key still in use may interrupt data access or service operation.
Remediation
Keep required keys at status = "Enabled". Confirm the reason before re-enabling a key disabled for incident response or retirement.
Examples
The examples change the key state from Disabled to Enabled. Do not apply this blindly to keys being retired or contained after compromise.
Before
hcl
resource "alicloud_kms_key" "key" {
description = "Hello KMS"
pending_window_in_days = "7"
status = "Disabled"
}
After
hcl
resource "alicloud_kms_key" "key" {
description = "Hello KMS"
pending_window_in_days = "7"
status = "Enabled"
}