Review customer-managed keys for an Alicloud OSS bucket

Use a customer-managed key when separate key control is required.

Description

OSS AES256 server-side encryption also encrypts stored data. A customer-managed KMS key is an option when the organization needs separate control over key access and lifecycle.

Potential impact

OSS-managed keys alone may not meet organizational key-control requirements in environments that require a customer-managed key.

Remediation

When required, set sse_algorithm = "KMS" and a kms_master_key_id in the same region, and configure permission to use the key. Migrate existing objects separately because their encryption does not change automatically.

Examples

The examples change default encryption from AES256 to a specified KMS key. Supply the actual key ID through the variable.

Before

hcl
resource "alicloud_oss_bucket" "bucket" {
  bucket = "bucket-170309-sserule"
  acl    = "private"

  server_side_encryption_rule {
    sse_algorithm = "AES256"
  }
}

After

hcl
resource "alicloud_oss_bucket" "bucket" {
  bucket = "bucket-170309-sserule"
  acl    = "private"

  server_side_encryption_rule {
    sse_algorithm     = "KMS"
    kms_master_key_id = var.kms_key_id
  }
}

References