Showing posts with label community. Show all posts
Showing posts with label community. Show all posts

Tuesday, July 18, 2017

AWS - How to encrypt instance launched from a community AMI ?



When we launch a instance from a public community AMI like ubuntu , centos etc, the volume will launch unencrypted. It is because Amazon EBS encryption uses AWS Key Management Service (AWS KMS) customer master keys (CMK) when creating encrypted volumes and any snapshots created from them. The first time we create an encrypted volume in a region, a default CMK is created for us automatically. This key is used for Amazon EBS encryption unless we select a CMK that we created separately using AWS KMS. Now this makes sense since every AWS customer needs to launch from this same public AMI, and we can't all share the same key.

However post launch we can encrypt this and then put our data on this.



1. Post launch , locate the volume to be encrypted. If you see , this volume will be unencrypted.



2. Create a snapshot of this volume.



3. Once snapshot is created and available, locate it and copy the snapshot , while copying there is an option to encrypt the volume.



4. copy it and locate new snapshot which is encrypted and create a AMI using this snapshot.