Skip to content

Commit db6991d

Browse files
committed
Enable EBS encryption by default.
A lot of security benchmarks and guides recommend to use encryption for EBS volumes. This setting enables encryption for all new EBS volumes by default even if you did not choose *Encrypted* when created it.
1 parent dbb3e95 commit db6991d

File tree

3 files changed

+40
-1
lines changed

3 files changed

+40
-1
lines changed

terraform/layer1-aws/.terraform.lock.hcl

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

terraform/layer1-aws/ebs.tf

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
resource "aws_ebs_encryption_by_default" "this" {
2+
enabled = true
3+
}

terraform/layer2-k8s/.terraform.lock.hcl

Lines changed: 36 additions & 0 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)