ApsaraDB for ClickHouse offers a free cloud disk encryption feature that encrypts the entire data disk at the block storage level. This protects your data by ensuring that even if a data backup is compromised, its contents remain undecipherable.
Features
After you create and attach an encrypted cloud disk to an ECS instance, the service automatically encrypts the following data:
-
Data at rest on the cloud disk.
-
Data in transit between the cloud disk and the instance (encryption of system disk data is not supported).
-
All snapshots created from the encrypted cloud disk.
Usage notes
-
Enterprise Edition clusters of ApsaraDB for ClickHouse do not support cloud disk encryption.
-
You can enable cloud disk encryption only when you create a Community-compatible Edition cluster. You cannot enable this feature for an existing cluster.
-
After you enable cloud disk encryption, you cannot disable it.
-
After you enable cloud disk encryption, snapshots of the instance and instances created from these snapshots are also automatically encrypted.
Cluster impact
-
Cloud disk encryption is transparent to your services and does not require any changes to your applications.
-
Cloud disk encryption does not significantly impact performance.
Billing
Cloud disk encryption is a free feature. You are not charged extra for read and write operations on the disk.
Key Management Service (KMS) incurs charges for key management and API calls. For more information, see KMS 1.0 billing.
Enable cloud disk encryption
When you create a cluster, configure the following parameters:
-
For Encryption Type, select cloud disk encryption.
-
Select an encryption key. If you have not created a key, follow the on-screen instructions to enable Key Management Service (KMS) and then create a key.
Note-
The cloud disk encryption feature of ApsaraDB for ClickHouse supports only user-created service keys. When you create a standard key, you must set Rotation Period to Not Enabled. For more information about how to create a key, see Create a key.
-
When you authorize KMS activation, ActionTrail records this operation. For more information, see Use ActionTrail to query the operational events of Key Management Service.
-
-
Click Buy and Start to create the encrypted cloud disk.
View the encryption key
-
Log on to the ApsaraDB for ClickHouse console.
-
On the Clusters page, go to the Clusters of Community-compatible Edition tab, and then click the ID of the target cluster.
-
On the Cluster Information page, in the Cluster Properties section, find the Key.
