Description
OSS AES256 server-side encryption also encrypts stored data. A customer-managed KMS key is an option when the organization needs separate control over key access and lifecycle.
Potential impact
OSS-managed keys alone may not meet organizational key-control requirements in environments that require a customer-managed key.
Remediation
When required, set sse_algorithm = "KMS" and a kms_master_key_id in the same region, and configure permission to use the key. Migrate existing objects separately because their encryption does not change automatically.
Examples
The examples change default encryption from AES256 to a specified KMS key. Supply the actual key ID through the variable.
Before
hcl
resource "alicloud_oss_bucket" "bucket" {
bucket = "bucket-170309-sserule"
acl = "private"
server_side_encryption_rule {
sse_algorithm = "AES256"
}
}
After
hcl
resource "alicloud_oss_bucket" "bucket" {
bucket = "bucket-170309-sserule"
acl = "private"
server_side_encryption_rule {
sse_algorithm = "KMS"
kms_master_key_id = var.kms_key_id
}
}