|
| 1 | +--- |
| 2 | +meta: |
| 3 | + title: Setting up Encryption at Rest for your Managed Databases with the Scaleway API |
| 4 | + description: This page explains how to set up Encryption at Rest for your Managed Databases with the Scaleway API. |
| 5 | +content: |
| 6 | + h1: Setting up Encryption at Rest for your Managed Databases with the Scaleway API |
| 7 | + paragraph: This page explains how to set up Encryption at Rest for your Managed Databases with the Scaleway API. |
| 8 | +tags: managed-database postgresql mysql encryption at rest |
| 9 | +dates: |
| 10 | + validation: 2024-12-19 |
| 11 | + posted: 2024-12-19 |
| 12 | +categories: |
| 13 | + - managed-databases |
| 14 | + - postgresql-and-mysql |
| 15 | +--- |
| 16 | + |
| 17 | +Encryption at rest allows you to permanently encrypt your database data. The data is encrypted at volume level using [LUKS](https://en.wikipedia.org/wiki/Linux_Unified_Key_Setup). The management of the encryption key is done by Scaleway. |
| 18 | + |
| 19 | +The feature can be activated upon Database Instance creation via the console and the API, or after creation exclusively through the API with the [upgrade endpoint](https://www.scaleway.com/en/developers/api/managed-database-postgre-mysql/#path-database-instances-upgrade-a-database-instance). |
| 20 | + |
| 21 | +<Message type="important"> |
| 22 | + - Once activated on a Database Instance, encryption at rest cannot be disabled. |
| 23 | + - All databases, data (including logs), and snapshots will be encrypted. Logical backup encryption is not currently available. |
| 24 | + - Enabling encryption means your database data will be copied into a new, encrypted block volume. This takes approximately 1 hour per 100 GB of storage. When switching volumes, expect a few seconds of downtime towards the end of the copying process. Refer to the [Encryption at rest performance benchmark on Database Instances](/managed-databases/postgresql-and-mysql/reference-content/encryption-at-rest-performance-benchmark) page. |
| 25 | +</Message> |
| 26 | + |
| 27 | +## Creating a Database Instance with encryption at rest |
| 28 | + |
| 29 | +1. Edit the POST request payload you will use to create your Database Instance. Make sure you include the `encryption` parameter and set the `enabled` attribute to `true`. |
| 30 | + <Message type="note"> |
| 31 | + In all examples below the UUIDs, passwords and IP addresses displayed are not real. For more details about the parameters shown, refer to the [Managed Databases for PostgreSQL and MySQL API documentation](https://www.scaleway.com/en/developers/api/managed-database-postgre-mysql/) |
| 32 | + </Message> |
| 33 | + |
| 34 | + ```json |
| 35 | + '{ |
| 36 | + "project_id": "d8e65f2b-cce9-40b7-80fc-6a2902db6826", |
| 37 | + "name": "myDB", |
| 38 | + "engine": "PostgreSQL-15", |
| 39 | + "tags": ["foo", "bar"], |
| 40 | + "is_ha_cluster": true, |
| 41 | + "node_type": "db-pro2-xxs", |
| 42 | + "disable_backup": false, |
| 43 | + "user_name": "my_initial_user", |
| 44 | + "password": "thiZ_is_v0ry_s3cret", |
| 45 | + "volume_type": "sbs_5k", |
| 46 | + "volume_size": "30000000000", |
| 47 | + "encryption": { |
| 48 | + "enabled": true |
| 49 | + } |
| 50 | + }' |
| 51 | + ``` |
| 52 | + |
| 53 | +2. Create a Database Instance by running the following command. Make sure you include the payload you edited in the previous step. |
| 54 | + ```bash |
| 55 | + curl -X POST \ |
| 56 | + -H "X-Auth-Token: $SCW_SECRET_KEY" \ |
| 57 | + "Content-Type: application/json" \ |
| 58 | + https://api.scaleway.com/rdb/v1/regions/$SCW_REGION/instances \ |
| 59 | + -d '{ |
| 60 | + "project_id": "d8e65f2b-cce9-40b7-80fc-6a2902db6826", |
| 61 | + "name": "myDB", |
| 62 | + "engine": "PostgreSQL-15", |
| 63 | + "tags": ["foo", "bar"], |
| 64 | + "is_ha_cluster": true, |
| 65 | + "node_type": "db-pro2-xxs", |
| 66 | + "disable_backup": false, |
| 67 | + "user_name": "my_initial_user", |
| 68 | + "password": "thiZ_is_v0ry_s3cret", |
| 69 | + "volume_type": "sbs_5k", |
| 70 | + "volume_size": "30000000000", |
| 71 | + "encryption": { |
| 72 | + "enabled": true |
| 73 | + } |
| 74 | + }' |
| 75 | + ``` |
| 76 | + You should get a response like the following confirming that the Database Instance was created, and encryption at rest is enabled. |
| 77 | + |
| 78 | + ```json |
| 79 | + { |
| 80 | + "id": "f5122f66-fb50-4cef-aa02-487ef4fc1af0", |
| 81 | + "name": "myDB", |
| 82 | + "organization_id": "895693aa-3915-4896-8761-c2923b008be7", |
| 83 | + "project_id": "d8e65f2b-cce9-40b7-80fc-6a2902db6826", |
| 84 | + "status": "ready", |
| 85 | + "engine": "PostgreSQL-15", |
| 86 | + "endpoint": { |
| 87 | + "ip": "198.51.100.0", |
| 88 | + "port": 22245, |
| 89 | + "name": null |
| 90 | + }, |
| 91 | + "tags": [ |
| 92 | + "foo", |
| 93 | + "bar" |
| 94 | + ], |
| 95 | + "settings": [], |
| 96 | + "backup_schedule": { |
| 97 | + "frequency": 24, |
| 98 | + "retention": 7, |
| 99 | + "disabled": true |
| 100 | + }, |
| 101 | + "is_ha_cluster": true, |
| 102 | + "read_replicas": [], |
| 103 | + "node_type": "db-pro2-xxs", |
| 104 | + "volume": { |
| 105 | + "type": "sbs_5k", |
| 106 | + "size": 30000000000 |
| 107 | + }, |
| 108 | + "encryption": { |
| 109 | + "enabled": true |
| 110 | + }, |
| 111 | + "created_at": "2019-04-19T16:24:52.591417Z", |
| 112 | + "region": "fr-par" |
| 113 | + } |
| 114 | + ``` |
| 115 | + |
| 116 | +## Enabling encryption at rest in an existing Database Instance |
| 117 | + |
| 118 | +To enable encryption at rest after a Database Instance has already been created, you can use the upgrade endpoint of the Managed Databases API. |
| 119 | + |
| 120 | +Run the following command. Make sure you replace the `instance_id` in the endpoint, and the `enable_encryption` parameter set to `true` |
| 121 | + |
| 122 | + ```json |
| 123 | + curl -X POST \ |
| 124 | + -H "X-Auth-Token: $SCW_SECRET_KEY" \ |
| 125 | + -H "Content-Type: application/json" \ |
| 126 | + -d '{ |
| 127 | + "enable_encryption": true |
| 128 | + }' \ |
| 129 | + "https://api.scaleway.com/rdb/v1/regions/fr-par/instances/{instance_id}/upgrade" |
| 130 | + ``` |
| 131 | + |
| 132 | +If the operation is successful, you see an output containing all the details of your Database Instance, including `"encryption":{"enabled":true}`. |
| 133 | + |
0 commit comments