All Products
Search
Document Center

E-MapReduce:Enable system disk encryption

Last Updated:Mar 26, 2026

System disk encryption protects the operating system, program files, and other system-related data on an E-MapReduce (EMR) cluster's system disk. If your business has security compliance requirements, enable this feature to safeguard data privacy and security without building or maintaining a key management infrastructure.

Important

System disk encryption cannot be disabled after it is enabled. Enable this feature only when your use case requires it.

Prerequisites

Before you begin, ensure that you have:

Limitations

ConstraintDetails
Supported disk typesEnterprise SSDs (ESSDs), standard SSDs, and ultra disks. Local disks cannot be encrypted.
TimingEncryption can only be enabled at cluster creation time. You cannot enable it on an existing cluster.

Enable system disk encryption

  1. Log on to the EMR console. In the left-side navigation pane, click EMR on ECS.

  2. On the EMR on ECS page, click Create Cluster.

  3. In the Basic Configuration step, click the more icon in the Advanced Settings section.

  4. Turn on System Disk Encryption and select a CMK from the drop-down list.

    System Disk Encryption toggle and CMK selector

  5. Complete the remaining cluster configuration — software and hardware settings, basic information, and order confirmation. For details, see Create a cluster.

Related topics