Description
When encryption at rest is disabled, NAS stores file data without encryption. Apply suitable encryption at creation when shared storage holds application files or business data.
encrypt_type = "0" selects no encryption, while 1 uses a NAS-managed key. Encryption at rest does not replace mount permissions or encryption in transit.
Potential impact
- Sensitive files may not meet encryption-at-rest requirements.
- An incident exposing stored data would lack the protection provided by storage encryption.
Remediation
- Set
encrypt_typeto1or the required customer-key option on a supported file-system type. - Encryption cannot be enabled later on an existing file system. Migrate data to a new encrypted file system, verify it, then switch mount paths.
- Check encryption, access permissions, protection in transit and backups together.
Examples
These excerpts compare encryption for new file systems. Review Terraform replacement and data migration before applying changes to an existing file system.
Before
hcl
resource "alicloud_nas_file_system" "unencrypted_fs" {
protocol_type = "NFS"
storage_type = "Performance"
description = "tf-testAccNasConfig"
encrypt_type = "0"
}
Encryption at rest is not used.
After
hcl
resource "alicloud_nas_file_system" "encrypted_fs" {
protocol_type = "NFS"
storage_type = "Performance"
description = "tf-testAccNasConfig"
encrypt_type = "1"
}
A NAS-managed key provides encryption. This setting is encrypted even without a separate customer-managed key.