Data encryption using KMS
KMS encryption is server-side encryption using a key managed by KMS. KMS is a security management service launched by Tencent Cloud, using a third-party-certified hardware security module (HSM) to generate and protect keys. KMS allows users to easily create and manage keys, meeting their key management needs for multiple applications and services, while satisfying regulatory and compliance requirements.
To use KMS to encrypt CLS log topics, activate KMS and authorize the CLS service role to access KMS resources. If a Tencent Cloud managed CMK for CLS is not available in KMS, the CLS will automatically create a key for you. Notes:
Currently, CLS data encryption is available only in Beijing, Shanghai, and Guangzhou regions.
Using KMS encryption will incur an additional cost, which will be charged by KMS. For more information, see KMS Billing Overview. The encryption feature can be enabled only when you create a log topic, and cannot be disabled once enabled.
Directions
1. Log in to the CLS console, select Log Topic, and click Create Log Topic. 2. In the pop-up window, click Advanced Settings and select Enable data encryption.
문제 해결에 도움이 되었나요?