elastic / elastic/roadmap

Encryption at rest with customer-managed keys in existing Elastic Cloud deployments [GA]

Open
#362 0 comments 0 reactions 1 assignee Claimed by @alxchalkias View on GitHub
Component: Elastic Cloud Hosted product-area:platform
Dominant language
No language data
Stars
6
Forks
1
PR merge metrics
No merged PRs in 30d

Description

**What the feature is and who it's for:**. This feature is an essential security and compliance measure. Administrators can configure their existing Elastic Cloud Hosted deployments to use their encryption keys from AWS KMS, Azure Key Vault or Google KMS to encrypt their data and snapshots at rest and do so without downtime. Previously, encryption at rest was only supported for new deployments, where customer-managed keys were added at deployment creation time, or for existing deployments with Elastic-managed keys.

**Value proposition:** Using a customer-managed key helps protect against threats related to the management and control of encryption keys. While it does not directly protect against any specific types of attacks or threats, the ability to keep control over your own keys can help mitigate certain types of threats, such as insider threats or compromised physical infrastructure. This enhancement not only enables security and compliance but also removes the need to migrate data to a new deployment.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.