CloudForming Encrypted Servers by Default

1 min read

AWS Today have announced a new EC2 Setting:

https://aws.amazon.com/blogs/aws/new-opt-in-to-default-encryption-for-new-ebs-volumes/

The question on everyone’s mind is:

Does this Encrypt when I build a server using CloudFormation using a base AMI from AWS marketplace?

Having just tested this the answer is Yes!

The next question on everyone’s mind is:

Does it Encrypt the Root Volume?

Having just tested this the answer is Yes!

Be sure to change the Default Key when setting Always Encrypt New EBS Volumes to use a CMK of your own and be mindful the settings are per region.