Description
An unencrypted ECS disk provides no encryption protection for stored data. Disk encryption protects that data using a KMS key.
Potential impact
Exposure of the storage medium can reveal plaintext data and violate encryption-at-rest requirements.
Remediation
Set encrypted = true for new disks and specify a key with kms_key_id when needed. An existing plaintext disk cannot be encrypted in place; create an encrypted copy and migrate the data.
Examples
The examples use the legacy alicloud_disk resource form. Supply an available KMS key ID and preserve data before replacing the disk.
Before
hcl
resource "alicloud_disk" "data_disk" {
availability_zone = "cn-beijing-b"
name = "New-disk"
description = "Hello ecs disk."
category = "cloud_efficiency"
size = "30"
encrypted = false
}
After
hcl
resource "alicloud_disk" "data_disk" {
availability_zone = "cn-beijing-b"
name = "New-disk"
description = "Hello ecs disk."
category = "cloud_efficiency"
size = "30"
encrypted = true
kms_key_id = var.kms_key_id
}