All Products
Search
Document Center

E-MapReduce:Enable data disk encryption

Last Updated:Jun 20, 2026

Once enabled, data disk encryption encrypts data on data disks, both in transit and at rest. This feature helps you meet security and compliance requirements by protecting data privacy and providing a security boundary for your business data, without requiring you to build and maintain a key management infrastructure.

Background information

For more information about data disk encryption, see Encrypt cloud disks.

Prerequisites

Key Management Service (KMS) must be activated and a key must be created. For more information, see Purchase a dedicated KMS instance and Create a key.

Limitations

  • Encryption is supported only for ESSD, standard SSD, and ultra disk. This feature is not supported for local disk.
  • You can enable data disk encryption only when creating a new cluster, not for an existing one.

Precautions

Once enabled, data disk encryption cannot be disabled. Carefully consider whether to enable this feature.

Procedure

  1. Log on to the EMR on ECS console. In the top navigation bar, select a region and a resource group. The cluster is created in the selected region, and this choice cannot be changed later. By default, the resource group displays all resources in your account.
  2. Click Create Cluster.

  3. In the Basic Configuration step, click the more icon in the Advanced Settings section.
  4. Turn on the Data Disk Encryption switch and select a key from the drop-down list.
    For example, you can select Default Service CMK.

    When you create a cluster, you must also complete the Software Configuration, Hardware Configuration, Basic Configuration, and Confirm Order steps. For more information, see Create a cluster.