Data disk encryption protects data on data disks both in transit and at rest. You can meet security and compliance requirements, protect data privacy, and provide a security boundary for your business data without building or maintaining a key management infrastructure.
Background information
For more information about data disk encryption, see Encrypt cloud disks.
Prerequisites
Key Management Service (KMS) must be activated and a key must be created. For more information, see Purchase a dedicated KMS instance and Create a key.
Limitations
- Encryption is supported only for ESSD, standard SSD, and ultra disk. This feature is not supported for local disk.
- You can enable data disk encryption only when creating a new cluster, not for an existing one.
Precautions
Data disk encryption cannot be disabled after it is enabled. Evaluate your requirements before you enable this feature.
Procedure
- Log on to the EMR on ECS console. In the top navigation bar, select a region and a resource group. The cluster is created in the selected region, and this choice cannot be changed later. By default, the resource group displays all resources in your account.
-
Click Create Cluster.
- In the Basic Configuration step, click the
icon in the Advanced Settings section. - Turn on the Data Disk Encryption switch and select a key from the drop-down list.
For example, you can select Default Service CMK.
When you create a cluster, you must also complete the Software Configuration, Hardware Configuration, Basic Configuration, and Confirm Order steps. For more information, see Create a cluster.