Review KMS keys for Alicloud ECS data disks

Verify the encryption state and KMS key of ECS data disks against your key-management requirements.

Description

A customer-managed KMS key gives your organization control over key permissions and lifecycle. An absent kms_key_id does not prove that a disk is unencrypted. An encrypted disk can use a service key or the key selected by account-level default encryption.

Potential impact

  • The actual key may not meet organizational key-management or audit requirements.
  • Disabling or deleting a key in use can make encrypted data inaccessible.

Remediation

  • Verify the actual disk encryption and key. If a customer-managed key is required, set encrypted = true and an approved kms_key_id.
  • Grant ECS permission to use the key and control key disabling and deletion.
  • Existing disks cannot be converted merely by changing encryption settings. Inspect replacement in the provider plan and prepare any data migration and attachment cutover.

Examples

These are excerpts using the legacy alicloud_disk form, renamed to alicloud_ecs_disk from provider 1.122.0. Replace the masked key ID with an actual usable key ID.

Encrypted disk without an explicit key

hcl
resource "alicloud_disk" "ecs_disk" {
  availability_zone = "cn-beijing-b"
  name              = "New-disk"
  description       = "Hello ecs disk."
  category          = "cloud_efficiency"
  size              = "30"
  encrypted         = true

  tags = {
    Name = "TerraformTest"
  }
}

Encryption is enabled. Check whether the selected key meets your requirements.

Encrypted disk with an explicit key

hcl
resource "alicloud_disk" "ecs_disk" {
  availability_zone = "cn-beijing-b"
  name              = "New-disk"
  description       = "Hello ecs disk."
  category          = "cloud_efficiency"
  size              = "30"
  encrypted         = true
  kms_key_id        = "2a6767f0-a16c-4679-a60f-13bf*****"

  tags = {
    Name = "TerraformTest"
  }
}

A key ID is specified. The key and permissions must be valid; this change does not immediately replace the key of an existing disk.

References