CloudForming Encrypted Servers by Default
AWS Today have announced a new EC2 Setting:
https://aws.amazon.com/blogs/aws/new-opt-in-to-default-encryption-for-new-ebs-volumes/
The question on everyone’s mind is:
Does this Encrypt when I build a server using CloudFormation using a base AMI from AWS marketplace?
Having just tested this the answer is Yes!
The next question on everyone’s mind is:
Does it Encrypt the Root Volume?
Having just tested this the answer is Yes!
Be sure to change the Default Key when setting Always Encrypt New EBS Volumes to use a CMK of your own and be mindful the settings are per region.