Review data-disk encryption in Alicloud Launch Templates

Verify encryption for data disks created from an ECS Launch Template.

Description

Launch Templates are reusable deployment settings. If their data disks are created without encryption, the same gap in stored-data protection can recur across instances.

In the legacy alicloud_launch_template, the data-disk encrypted setting belongs inside data_disks. It does not ensure encryption of all system disks; verify the actual settings for each disk type separately.

Potential impact

  • Sensitive data that requires disk encryption may be stored without it.
  • Reusing the template can increase the number of disks that do not meet organizational protection requirements.

Remediation

  • Set encrypted = true for data disks and check encryption support and key permissions for the disk type and region.
  • Verify the template version being used and the actual encryption of newly created instances. Updating a template does not convert existing disks.
  • Configure system-disk encryption separately. For new configurations, check the alicloud_ecs_launch_template attributes in your provider version.

Examples

These excerpts compare data-disk settings in the legacy alicloud_launch_template form. Supply suitable image, instance-type and network inputs, and preserve the resource address when modifying an existing configuration.

Before

hcl
resource "alicloud_launch_template" "unencrypted_template" {
  name                          = "tf-test-template"
  image_id                      = data.alicloud_images.images.images[0].id
  instance_type                 = data.alicloud_instances.instances.instances[0].instance_type
  system_disk_category          = "cloud_ssd"
  system_disk_size              = 40

  data_disks {
    category  = "cloud_ssd"
    size      = 40
    encrypted = false
  }
}

Encryption is not requested for the data disk. Verify the resulting disk, including the effects of account defaults.

After

hcl
resource "alicloud_launch_template" "encrypted_template" {
  name                          = "tf-test-template"
  image_id                      = data.alicloud_images.images.images[0].id
  instance_type                 = data.alicloud_instances.instances.instances[0].instance_type
  system_disk_category          = "cloud_ssd"
  system_disk_size              = 40

  data_disks {
    category  = "cloud_ssd"
    size      = 40
    encrypted = true
  }
}

Encryption is requested for the new data disk. Check system disks and existing disks separately.

References