After a data disk is encrypted, both data in transit and data at rest on the disk are encrypted. You can use this feature if your business has security compliance requirements. You can configure encryption to protect the privacy, autonomy, and security of data without the need to develop or maintain a key management infrastructure.
Background information
For more information about data disk encryption, see Encryption overview.
Prerequisites
Key Management Service (KMS) is activated and a customer master key (CMK) is created. For more information, see Purchase a dedicated KMS instance and Create a CMK.
Limits
- Only enhanced SSDs, standard SSDs, and ultra disks can be encrypted. Local disks cannot be encrypted.
- You can enable data disk encryption only when you create a cluster. You cannot enable data disk encryption for an existing cluster.
Precautions
You cannot disable data disk encryption after it is enabled. We recommend that you enable this feature only when it is necessary.
Procedure
- Go to the EMR on ECS page.
- On the EMR on ECS page, click Create Cluster.
- In the Basic Configuration step, click the icon in the Advanced Settings section.
- Turn on Data Disk Encryption and select a key from the drop-down list.
When you create the cluster, you need to configure the software and hardware, specify basic information, and confirm the order for the cluster. For more information about the configurations, see Create a cluster.