当您的业务因为安全需求或法规合规要求等原因,需要对存储在云盘上的数据进行加密保护时,您可以在ACK容器集群中使用云盘加密功能,无需构建、维护和保护自己的密钥管理基础设施,即可保护数据的隐私性和自主性。
使用BYOK创建加密云盘时,系统需要使用同一地域的密钥管理服务(KMS)提供的BYOK(Bring Your Own Key)。因此,首次通过控制台或者API使用云盘加密功能之前,您必须先开通密钥管理服务。
1. 创建BYOK
登录密钥管理服务控制台
创建BYOK并记录密钥ID:
2. 创建StorageClass使用BYOK
在ACK容器集群中新建StorageClass并配置encrypted: "true"
kmsKeyId: <your BYOK>
使用BYOK,示例如下:
$ cat storageclass-ssd-byok.yaml
apiVersion: storage.k8s.io/v1
kind: StorageClass
metadata:
name: alicloud-disk-ssd-byok
parameters:
type: cloud_ssd
encrypted: "true"
kmsKeyId: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
provisioner: alicloud/disk
reclaimPolicy: Delete
$ kubectl apply -f storageclass-ssd-byok.yaml
查看StorageClass:
$ kubectl get sc
NAME PROVISIONER AGE
alicloud-disk-available alicloud/disk 19m
alicloud-disk-efficiency alicloud/disk 19m
alicloud-disk-essd alicloud/disk 19m
alicloud-disk-ssd alicloud/disk 19m
alicloud-disk-ssd-byok alicloud/disk 28s
3. 创建示例应用创建并挂载云盘
$ cat deploy.yaml
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
name: disk-ssd-byok
spec:
accessModes:
- ReadWriteOnce
storageClassName: alicloud-disk-ssd-byok
resources:
requests:
storage: 20Gi
---
kind: Pod
apiVersion: v1
metadata:
name: disk-pod-ssd-byok
spec:
containers:
- name: disk-pod-byok
image: nginx
volumeMounts:
- name: disk-pvc-byok
mountPath: "/mnt"
restartPolicy: "Never"
volumes:
- name: disk-pvc-byok
persistentVolumeClaim:
claimName: disk-ssd-byok
$ kubectl apply -f deploy.yaml
查看PV:
$ kubectl get pv
NAME CAPACITY ACCESS MODES RECLAIM POLICY STATUS CLAIM STORAGECLASS REASON AGE
d-j6c5jezzajt9ri47lvjs 20Gi RWO Delete Bound default/disk-ssd-byok alicloud-disk-ssd-byok 8s
我们可以在 ECS控制台 查看 volume id为 d-j6c5jezzajt9ri47lvjs
的云盘是否已加密:
4. 报错及解决办法
报错信息1:
provision volume with StorageClass "alicloud-disk-ssd-zones-encrypt": Aliyun API Error: RequestId: DA0DD66A-38C0-4C91-98DB-A4D0B27A783A Status Code: 403 Code: UserNotInTheWhiteList Message: The user is not in byok white list.
解决办法:
给ecs开工单添加使用权限
报错信息2:
6bc5d686-1201-11ea-83de-0a58ac160203 Failed to provision volume with StorageClass "alicloud-disk-ssd-zones-encrypt": Aliyun API Error: RequestId: 81FB907C-210F-440F-8C3E-00DEE6BF2A47 Status Code: 403 Code: InvalidParameter.KMSKeyId.KMSUnauthorized Message: ECS service have no right to access your KMS.
解决办法:
用户账号需要添加AliyunECSDiskEncryptDefaultRole
5. 其他
更多关于云盘加密以及BYOK的介绍请参考:
https://help.aliyun.com/document_detail/107972.html