Bring Your Own Key (BYOK) for Encryption at Rest
Encryption at rest in Elastic Cloud: Bring your own key with AWS KMS

Encryption at rest in Elastic Cloud: Bring your own key with AWS KMS

8/1/2024

What this post added

This post details the technical implementation of BYOK for encryption at rest in Elastic Cloud using AWS KMS. It covers the architecture of the integration, prerequisites including KMS key creation (symmetric/multi-region, KMS/External/XKS origins) and Enterprise subscription level, the step-by-step process of creating an AWS KMS key and configuring its policy to grant Elastic access, and the integration of this key into an Elastic Cloud deployment. It also outlines verification steps and discusses key rotation and revocation mechanisms.

Read the original post ↗