Queries whether Transparent Data Encryption (TDE) is enabled for an ApsaraDB for MongoDB instance.
Operation description
For more information about TDE, see TDE.
Before you call this operation, make sure that the instance meets the following requirements:
The instance is a replica set or sharded cluster instance.
The storage engine of the instance is WiredTiger.
The database engine version of the instance is 4.0 or 4.2. If the database engine version is earlier than 4.0, you can call the UpgradeDBInstanceEngineVersion operation to upgrade the database engine.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
dds:DescribeDBInstanceTDEInfo |
get |
*Instance
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| DBInstanceId |
string |
Yes |
The instance ID. |
dds-bpxxxxxxxx |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
|||
| TDEStatus |
string |
The TDE status. Valid values:
|
enabled |
| RequestId |
string |
The request ID. |
F4DD0E29-361B-42F2-9301-B0048CCCE5D6 |
| RoleARN |
string |
指定待授权角色的全局资源描述符 ARN(Alibaba Cloud Resource Name)信息。 |
acs:ram::123456789012****:role/aliyunrdsinstanceencryptiondefaultrole |
| EncryptionKey |
string |
实例的自定义密钥。 目前仅以下地域支持 BYOK(Bring Your Own Key,用户可以自行管理和拥有加密密钥):
Note
支持 BYOK,用户可以管理且拥有密钥,系统将返回用户的自定义密钥;不支持 BYOK,用户不可管理密钥,系统将返回字符串 |
2axxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx |
| EncryptorName |
string |
加密算法。 |
aes-256-cbc |
Examples
Success response
JSON format
{
"TDEStatus": "enabled",
"RequestId": "F4DD0E29-361B-42F2-9301-B0048CCCE5D6",
"RoleARN": "acs:ram::123456789012****:role/aliyunrdsinstanceencryptiondefaultrole",
"EncryptionKey": "2axxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx",
"EncryptorName": "aes-256-cbc"
}
Error codes
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.