For ApsaraDB for MyBase instances that use cloud disks, Alibaba Cloud provides the disk encryption feature at no additional cost. This feature encrypts the entire data disk at the block storage level. This protects your data by ensuring that compromised backups cannot be decrypted.
Prerequisites
-
You can enable disk encryption only when you create a MySQL or PostgreSQL instance. You cannot enable disk encryption for an existing instance. For more information, see Create an ApsaraDB for MyBase MySQL instance and Create an ApsaraDB for MyBase PostgreSQL instance (purchases discontinued).
-
The storage type for the instance must be enhanced SSD (ESSD).
-
The product edition for the instance must be high-availability edition.
-
The instance must be in one of the following regions:
-
China (Hangzhou)
-
China (Shanghai)
-
China (Qingdao)
-
China (Beijing)
-
China (Shenzhen)
-
China (Hong Kong)
-
Singapore
-
Malaysia (Kuala Lumpur)
-
Indonesia (Jakarta)
-
Germany (Frankfurt)
-
Billing
Disk encryption is a free feature. You are not charged extra for any read or write operations on encrypted disks.
Notes
-
After you enable disk encryption, you cannot disable it.
-
After you enable disk encryption, snapshots of the instance, and any new instances created from those snapshots, are also automatically encrypted.
-
Disk encryption is transparent to your applications, requiring no modifications and having no impact on your business.
Enable disk encryption
When you create a MySQL or PostgreSQL instance, select Enhanced SSD (Recommended) for the storage type, select the Disk Encryption checkbox, and then choose a key.
For information about how to create a key, see Create a key.