
8/1/2024
What this post added
This post details the technical implementation of BYOK for encryption at rest in Elastic Cloud using AWS KMS. It covers the architecture of the integration, prerequisites including KMS key creation (symmetric/multi-region, KMS/External/XKS origins) and Enterprise subscription level, the step-by-step process of creating an AWS KMS key and configuring its policy to grant Elastic access, and the integration of this key into an Elastic Cloud deployment. It also outlines verification steps and discusses key rotation and revocation mechanisms.