Tair provides the transparent data encryption (TDE) feature. This feature allows you to encrypt and decrypt Redis Database (RDB) files. You can enable TDE in the Tair console to allow the system to encrypt and decrypt RDB files. This improves data security and compliance.
Prerequisites
The instance is a Tair (Enterprise Edition) DRAM-based instance.
The instance is deployed in classic (local disk-based) mode.
The minor version of the instance is 1.7.1 or later. For information about how to update the minor version, see Update the minor version of an instance.
Background information
The TDE feature of Tair encrypts RDB files before they are written to disks and decrypts RDB files when they are read from disks to the memory. TDE does not increase the sizes of RDB files. When you use TDE, you do not need to modify your client.
Impacts
You cannot disable TDE after it is enabled. You must evaluate the impacts on your business before you enable TDE. Take note of the following impacts:
After TDE is enabled for an instance, the instance cannot be migrated across zones. For more information, see Migrate an instance across zones.
After TDE is enabled for an instance, the offline key analysis feature is not supported for the instance. For more information, see Use the offline key analysis feature.
After TDE is enabled for an instance, the instance cannot be converted into a child instance of a distributed instance. For more information, see Create a distributed instance.
After TDE is enabled for an instance, the instance cannot be migrated or synchronized by using Data Transmission Service (DTS).
Usage notes
TDE can be enabled for an instance but not for a key or a database.
TDE encrypts RDB files that are written to disks, such as dump.rdb.
Key Management Service (KMS) generates and manages the keys used by TDE. Tair does not provide keys or certificates required for encryption. For more information about KMS, see What is Key Management Service?
Instances for which TDE is enabled cannot be restored from the recycle bin.
Procedure
Log on to the Tair console and go to the Instances page. In the top navigation bar, select the region in which the instance that you want to manage resides. Then, find the instance and click the instance ID.
In the left-side navigation pane, click TDE Settings.
Turn on TDE Status to enable TDE.
In the dialog box that appears, select Use Automatically Generated Key or Use Custom Key and then click OK.
When the instance state changes from Modifying TDE to Running, TDE is enabled.
Related API operations
API operation | Description |
Enables TDE for a Tair instance. You can use automatically generated keys or existing custom keys. | |
Queries whether TDE is enabled for a Tair instance. | |
Queries the custom keys that are available for a Tair instance to use TDE. | |
Queries the details of a custom key for a Tair instance to use TDE. | |
Queries whether a Tair instance has the permissions to use KMS. |
FAQ
How do I decrypt an encrypted RDB file?
RDB files cannot be decrypted. You can restore the file to a new instance. After the restoration is complete, the data is automatically decrypted.
Why is the data read by clients still displayed in plaintext?
Only RDB files written to disks are encrypted. The data read by clients is from memory and is not encrypted. That is why it is displayed in plaintext.