Description
A customer-managed KMS key gives your organization control over key permissions and lifecycle. An absent kms_key_id does not prove that a disk is unencrypted. An encrypted disk can use a service key or the key selected by account-level default encryption.
Potential impact
- The actual key may not meet organizational key-management or audit requirements.
- Disabling or deleting a key in use can make encrypted data inaccessible.
Remediation
- Verify the actual disk encryption and key. If a customer-managed key is required, set
encrypted = trueand an approvedkms_key_id. - Grant ECS permission to use the key and control key disabling and deletion.
- Existing disks cannot be converted merely by changing encryption settings. Inspect replacement in the provider plan and prepare any data migration and attachment cutover.
Examples
These are excerpts using the legacy alicloud_disk form, renamed to alicloud_ecs_disk from provider 1.122.0. Replace the masked key ID with an actual usable key ID.
Encrypted disk without an explicit key
hcl
resource "alicloud_disk" "ecs_disk" {
availability_zone = "cn-beijing-b"
name = "New-disk"
description = "Hello ecs disk."
category = "cloud_efficiency"
size = "30"
encrypted = true
tags = {
Name = "TerraformTest"
}
}
Encryption is enabled. Check whether the selected key meets your requirements.
Encrypted disk with an explicit key
hcl
resource "alicloud_disk" "ecs_disk" {
availability_zone = "cn-beijing-b"
name = "New-disk"
description = "Hello ecs disk."
category = "cloud_efficiency"
size = "30"
encrypted = true
kms_key_id = "2a6767f0-a16c-4679-a60f-13bf*****"
tags = {
Name = "TerraformTest"
}
}
A key ID is specified. The key and permissions must be valid; this change does not immediately replace the key of an existing disk.