Enables account-level default encryption for block storage in a specified region.
Operation description
The EBS account-level default encryption feature is currently available only in specific regions and for specific users. If you need this feature, submit a ticket.
-
Before you begin
Resource Access Management (RAM) users require the
AliyunECSFullAccesspermission. For authorization details, see Grant permissions to a RAM user.Before enabling account-level default encryption for block storage, activate Key Management Service (KMS).
After account-level default encryption for block storage is enabled, only encrypted cloud disks can be created. For details, see Encrypted cloud disks - Limits.
-
Precautions
-
After account-level default encryption for block storage is enabled, all newly created pay-as-you-go or subscription cloud disks must be encrypted. You can use the KMS key ID configured for account-level default encryption for block storage, or specify a different KMS key ID.
-
When account-level default encryption for block storage is enabled for the first time, the service key is used by default.
-
-
Recommendations
Call DescribeDiskEncryptionByDefaultStatus and DescribeDiskDefaultKMSKeyId to query whether account-level default encryption for block storage is enabled in a specified region and the KMS key ID in use.
Call ModifyDiskDefaultKMSKeyId or ResetDiskDefaultKMSKeyId to modify or reset the KMS key for account-level default encryption for block storage.
Call DisableDiskEncryptionByDefault to disable account-level default encryption for block storage in a specified region.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
ecs:EnableDiskEncryptionByDefault |
none |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| RegionId |
string |
Yes |
The region ID. You can call DescribeRegions to query the most recent region list. |
cn-hangzhou |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
Schema of Response。 |
||
| RequestId |
string |
The request ID. |
473469C7-AA6F-4DC5-B3DB-A3DC0DE3C83E |
Examples
Success response
JSON format
{
"RequestId": "473469C7-AA6F-4DC5-B3DB-A3DC0DE3C83E"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | InvalidParameter.Encrypted.KmsNotEnabled | KMS must be enabled for encrypted disks. | KMS is not activated. You must activate KMS before you can encrypt disks. |
| 400 | InvalidParameter.KmsNotEnabled | The operation failed because KMS is not activated. Please activate KMS in the KMS console and try again. | |
| 403 | Abs.InvalidAction.RegionNotSupport | This region does not support this action. | The operation is not supported in the region. |
| 403 | InvalidOperation.DefaultEncryptionAlreadyEnabled | The specified region is already default encryption settings. | The region has enabled cloud disk encryption by default. |
| 403 | InvalidParameter.RegionIdNotExists | The specified region does not exist. | |
| 403 | InvalidParameter.KMSKeyId.KMSUnauthorized | ECS service does not have permission to access your KMS key. Please verify that the specified KMS key has authorized the ECS service. | |
| 403 | InvalidOperation.KMSKeyIdNotFound | The specified KMSKeyId does not exist. Please verify that the key ID is correct and that the key resides in the current region. | |
| 403 | InvalidOperation.KMSServiceNotOpen | KMS service is currently not open. | The KMS service has not been enabled. |
| 403 | UserNotInTheWhiteList | The user is not in disk white list. | You are not authorized to manage the disk. Try again when you are authorized. |
| 403 | InvalidParameter.KMSKeyId.CMKNotEnabled | The specified KMS key must be in an enabled state. Please enable the key in the KMS console and try again. | |
| 403 | InvalidParameter.KMSKeyId.CMKUnauthorized | The specified KMS key is not authorized for the ECS service. Please grant the ECS service permission to use the key in the KMS console and try again. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.