Modifies the KMS key ID used for block storage account-level default encryption in a specified region.
Operation description
Resource Access Management (RAM) users require the
AliyunECSFullAccesspermission. For the authorization operation, see Grant permissions to a RAM user.Block storage account-level default encryption feature must be enabled in the specified region.
If you use a master key for the first time, grant the
AliyunECSDiskEncryptDefaultRolerole to ECS to allow ECS to access KMS resources. For details, see Grant permissions to access KMS keys by using a RAM role.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
ecs:ModifyDiskDefaultKMSKeyId |
update |
*All Resource
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| RegionId |
string |
Yes |
The region ID. You can call DescribeRegions to query the most recent region list. |
cn-hangzhou |
| KMSKeyId |
string |
Yes |
The KMS key ID. |
0e478b7a-4262-4802-b8cb-00d3fb40**** |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| RequestId |
string |
The request ID. |
473469C7-AA6F-4DC5-B3DB-A3DC0DE3C83E |
Examples
Success response
JSON format
{
"RequestId": "473469C7-AA6F-4DC5-B3DB-A3DC0DE3C83E"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | InvalidParameter.Encrypted.KmsNotEnabled | KMS must be enabled for encrypted disks. | KMS is not activated. You must activate KMS before you can encrypt disks. |
| 400 | InvalidParameter.KmsNotEnabled | The operation failed because KMS is not activated. Please activate KMS in the KMS console and try again. | |
| 403 | Abs.InvalidAction.RegionNotSupport | This region does not support this action. | The operation is not supported in the region. |
| 403 | InvalidParameter.RegionIdNotExists | The specified region does not exist. | |
| 403 | InvalidParameter.KMSKeyId.KMSUnauthorized | ECS service does not have permission to access your KMS key. Please verify that the specified KMS key has authorized the ECS service. | |
| 403 | InvalidOperation.KMSKeyIdNotFound | The specified KMSKeyId does not exist. Please verify that the key ID is correct and that the key resides in the current region. | |
| 403 | InvalidOperation.KMSServiceNotOpen | KMS service is currently not open. | The KMS service has not been enabled. |
| 403 | UserNotInTheWhiteList | The user is not in disk white list. | You are not authorized to manage the disk. Try again when you are authorized. |
| 403 | InvalidDefaultEncryption.NotFound | You have not configured default encryption setting in this region. | Cloud disk encryption by default has not been enabled for the region. |
| 403 | InvalidParameter.KMSKeyId.CMKNotEnabled | The specified KMS key must be in an enabled state. Please enable the key in the KMS console and try again. | |
| 403 | InvalidParameter.KMSKeyId.CMKUnauthorized | The specified KMS key is not authorized for the ECS service. Please grant the ECS service permission to use the key in the KMS console and try again. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.