Starting today, you can encrypt your EC2 volume with your own specific AWS KMS Key.
New Parameter: kmsKeyId
The Resource Name of the AWS Key Management Service master key that is used to create the encrypted volume, such as abcd1234-a123-456a-a12b-a123b4cd56ef
. Please note to use this parameter when the encrypted
parameter is set to true
Required: No
Type: String
Example
"blockDeviceMappings":[ { "deviceName":"/dev/sdf", "ebs":{ "encrypted":true, "kmsKeyId":"28921f1a-372e-99e7-m580-bhjdmjhas78", "volumeSize":10 } } ]