All Products
Search
Document Center

Key Management Service:Cloud services integrated with KMS

Last Updated:Jul 10, 2026

Alibaba Cloud services that integrate with KMS for data encryption.

Important

If your Alibaba Cloud service supports KMS encryption and the default service key or master key meets your needs, you do not need a separate KMS instance.

Workload data encryption

Service

Description

Related documentation

Elastic Compute Service (ECS)

ECS cloud disk encryption uses a service key by default, or a CMK you specify. Each cloud disk is associated with a CMK and data key for envelope encryption.

Data transferred between an ECS instance and its cloud disk is automatically encrypted and decrypted on the host, with negligible performance impact.

After you create an encrypted cloud disk and attach it to an ECS instance, the following data is encrypted:

  • Data at rest on the cloud disk

  • Data in transit between the disk and instance (data within the instance's operating system is not encrypted)

  • All snapshots created from the encrypted cloud disk (encrypted snapshots)

Encryption overview

Container Service for Kubernetes (ACK)

ACK supports KMS-based server-side encryption for two types of workload data:

  • Kubernetes Secrets

    Kubernetes Secrets store sensitive data such as passwords, TLS certificates, and image pull credentials in the cluster's etcd.

  • Volumes

    Volumes (cloud disks, OSS buckets, or NAS file systems) can each use their respective KMS encryption method.

Use KMS to encrypt secrets at rest

Container Registry (ACR)

ACR supports automatic namespace-level image signing to prevent man-in-the-middle attacks and unauthorized image use. Pushed images are signed based on matching rules, ensuring integrity from distribution to deployment.

Use Container Image Signing

Elastic Container Instance (ECI)

Each ECI Pod has a 30 GiB temporary storage space (expandable) for container images and runtime data. Enable encryption for this space to protect sensitive data.

Encrypt temporary storage spaces

Persistent storage data encryption

Service

Description

Related documentation

Object Storage Service (OSS)

  • OSS supports server-side encryption for uploaded data:

    • Upload: OSS encrypts received data before persisting it.

    • Download: OSS decrypts stored data and returns plaintext. The response header indicates server-side encryption was applied.

  • OSS provides two server-side encryption methods:

    • Server-side encryption with OSS-managed keys (SSE-OSS)

      An earlier method using OSS-internal keys. Simple to configure with no extra operations.

      Important

      OSS-managed keys cannot be tracked or audited in ActionTrail.

    • Server-side encryption with KMS (SSE-KMS)

      Integrates with KMS for key generation and management, providing higher security and compliance.

      • SSE-KMS supports two key types:

        • Service keys: Default keys that KMS automatically creates and manages for OSS. No manual creation required.

        • CMKs: Keys you create and manage in KMS. You control the full key lifecycle (creation, disabling, rotation) and can track usage in ActionTrail for compliance.

          Note

          Keys from a KMS instance shared through Resource Directory can also encrypt OSS data. Share KMS resources among multiple accounts.

      • Configuration methods

        SSE-KMS supports flexible encryption configurations:

        • Bucket-level: Set a default CMK for an entire bucket.

        • Object-level: Specify a CMK per object upload to override bucket defaults.

File Storage NAS

NAS encryption uses a service key by default. Each volume is assigned a unique CMK and data key for envelope encryption.

Server-side encryption

Tablestore

Tablestore encryption uses a service key by default, or a key you select. Each table is assigned a unique CMK and data key for envelope encryption.

None

Cloud Storage Gateway (CSG)

Encrypts data based on OSS encryption.

Manage shares

Microservices Engine (MSE)

MSE integrates with KMS to encrypt sensitive configuration data (data sources, tokens, usernames, and passwords), reducing the risk of plaintext leaks.

Configuration encryption

Cloud Backup

Cloud Backup supports server-side encryption of backup data using KMS keys. You can use KMS service keys or customer-managed keys (CMKs) to encrypt backup data from ECS instances, NAS file systems, OSS buckets, and other data sources, reducing the risk of data leaks.

KMS encryption

Database encryption

Service

Description

Related documentation

ApsaraDB RDS

RDS provides the following two data encryption methods:

  • Cloud disk encryption

    Free for RDS instances with cloud disks. Encrypts the entire data disk at the block storage level. The encryption key is protected by KMS and retrieved only on instance startup or migration.

  • Transparent Data Encryption (TDE)

    Available for MySQL and SQL Server. The TDE key is protected by KMS and retrieved only on instance startup or migration. You specify which databases or tables to encrypt. Data is encrypted before reaching any storage device or service, ensuring data files and backups remain in ciphertext.

ApsaraDB for MongoDB

Provides TDE. The encryption method is similar to RDS.

Configure TDE

PolarDB

OceanBase

Enable TDE

Tair (Redis OSS-compatible)

Enable TDE

Tair

Enable TDE

AnalyticDB

Encrypts the entire data disk at the block storage level, ensuring that leaked backups cannot be decrypted.

ApsaraDB for ClickHouse

Cloud disk encryption

Log data encryption

Service

Description

Related documentation

ActionTrail

Encrypt operational events delivered to OSS when you create a single-account or multi-account trail.

Simple Log Service (SLS)

SLS uses KMS to encrypt data at rest.

Data encryption

Big data and AI

Service

Description

Related documentation

MaxCompute

MaxCompute supports data encryption by using a service key or a CMK.

Data encryption

Platform for AI

Cloud services at each stage of the PAI data flow (compute engines, container services, data storage) support server-side encryption.

None

E-MapReduce

Data disk encryption protects both data in transit and data at rest, helping meet security and compliance requirements.

Enable data disk encryption

Additional use cases

Service

Description

Related documentation

CDN

Supports OSS server-side encryption when using an OSS bucket as origin.

Redirect requests to a private OSS bucket

ApsaraVideo Media Processing (MPS)

MPS supports two methods for protecting video content with KMS: proprietary encryption and standard HLS encryption.

None

ApsaraVideo VOD

VOD supports two methods for protecting video content with KMS: Alibaba Cloud video encryption and standard HLS encryption.

Hologres

Hologres uses KMS to encrypt data at rest, helping meet regulatory and security compliance requirements.

Data storage encryption

ApsaraVideo Live

Encrypts video data so that downloaded videos remain encrypted and cannot be redistributed. Prevents leaks and unauthorized hotlinking for copyrighted content such as online education, finance, industry training, and exclusive drama series.

Alibaba Cloud video encryption

Wuying Workspace Enterprise Edition

Enable disk encryption for system and data disks when creating a cloud computer.

Create a cloud computer