Description
Launch Templates are reusable deployment settings. If their data disks are created without encryption, the same gap in stored-data protection can recur across instances.
In the legacy alicloud_launch_template, the data-disk encrypted setting belongs inside data_disks. It does not ensure encryption of all system disks; verify the actual settings for each disk type separately.
Potential impact
- Sensitive data that requires disk encryption may be stored without it.
- Reusing the template can increase the number of disks that do not meet organizational protection requirements.
Remediation
- Set
encrypted = truefor data disks and check encryption support and key permissions for the disk type and region. - Verify the template version being used and the actual encryption of newly created instances. Updating a template does not convert existing disks.
- Configure system-disk encryption separately. For new configurations, check the
alicloud_ecs_launch_templateattributes in your provider version.
Examples
These excerpts compare data-disk settings in the legacy alicloud_launch_template form. Supply suitable image, instance-type and network inputs, and preserve the resource address when modifying an existing configuration.
Before
resource "alicloud_launch_template" "unencrypted_template" {
name = "tf-test-template"
image_id = data.alicloud_images.images.images[0].id
instance_type = data.alicloud_instances.instances.instances[0].instance_type
system_disk_category = "cloud_ssd"
system_disk_size = 40
data_disks {
category = "cloud_ssd"
size = 40
encrypted = false
}
}
Encryption is not requested for the data disk. Verify the resulting disk, including the effects of account defaults.
After
resource "alicloud_launch_template" "encrypted_template" {
name = "tf-test-template"
image_id = data.alicloud_images.images.images[0].id
instance_type = data.alicloud_instances.instances.instances[0].instance_type
system_disk_category = "cloud_ssd"
system_disk_size = 40
data_disks {
category = "cloud_ssd"
size = 40
encrypted = true
}
}
Encryption is requested for the new data disk. Check system disks and existing disks separately.