Alicloud disk is not encrypted

Encrypt data stored on disks.

Description

An unencrypted ECS disk provides no encryption protection for stored data. Disk encryption protects that data using a KMS key.

Potential impact

Exposure of the storage medium can reveal plaintext data and violate encryption-at-rest requirements.

Remediation

Set encrypted = true for new disks and specify a key with kms_key_id when needed. An existing plaintext disk cannot be encrypted in place; create an encrypted copy and migrate the data.

Examples

The examples use the legacy alicloud_disk resource form. Supply an available KMS key ID and preserve data before replacing the disk.

Before

hcl
resource "alicloud_disk" "data_disk" {
  availability_zone = "cn-beijing-b"
  name              = "New-disk"
  description       = "Hello ecs disk."
  category          = "cloud_efficiency"
  size              = "30"
  encrypted         = false
}

After

hcl
resource "alicloud_disk" "data_disk" {
  availability_zone = "cn-beijing-b"
  name              = "New-disk"
  description       = "Hello ecs disk."
  category          = "cloud_efficiency"
  size              = "30"
  encrypted         = true
  kms_key_id        = var.kms_key_id
}

References