Review customer-managed KMS keys for Alicloud NAS

Review NAS encryption and key-management requirements, using a customer-managed KMS key where needed.

Description

Customer-managed KMS keys support organizational control over NAS key permissions and lifecycle. NAS-managed keys also use KMS to encrypt data, so absence of a customer key does not establish that encryption is disabled.

Provider 1.293.0 documents encrypt_type = "1" for NAS-managed keys and 2 for customer-managed keys, with the latter supported on Extreme NAS. A value of 2 requires kms_key_id.

Potential impact

  • The actual key option may not meet organizational key-management requirements.
  • Disabling or deleting a customer key can make the file system inaccessible.

Remediation

  • Check actual encryption and the key, then decide whether customer key control is required on a supported file-system type.
  • Where required, set encrypt_type = "2" and a usable kms_key_id, granting NAS the necessary key permissions.
  • Encryption and the key cannot be changed after creation, so plan data migration for existing file systems. Check the effects of key deletion or disabling and the recovery procedure.

Examples

These compare different new file-system configurations. In the second excerpt, supply supported Extreme NAS capacity and zone values and an actual usable key ID. Existing file systems are not converted by simply changing these settings.

No explicit encryption configuration

hcl
resource "alicloud_nas_file_system" "nas_without_kms" {
  protocol_type = "NFS"
  storage_type  = "Performance"
  description   = "tf-testAccNasConfig"
}

Encryption is not specified for General-purpose NAS. The encryption default is 0; check the actual protection.

Extreme NAS with a customer key

hcl
resource "alicloud_nas_file_system" "nas_with_kms" {
  protocol_type = "NFS"
  storage_type  = "standard"
  file_system_type = "extreme"
  capacity         = var.nas_capacity
  zone_id          = var.nas_zone_id
  description   = "tf-testAccNasConfig"
  encrypt_type  = "2"
  kms_key_id    = "1234abcd-12ab-34cd-56ef-1234567890ab"
}

This creates a new Extreme NAS file system encrypted with a customer-managed key. Mount targets and access permissions require separate configuration.

References