Support for customer-managed keys (CMK) on the volume-level instead of Encryption-at-Rest
For some customers managing a set of low-latency workloads is crucial, so volume-based encryption using their own KMS encryption keys is preferred over the encryption-at-rest feature of the WiredTiger storage engine. https://docs.aws.amazon.com/kms/latest/developerguide/key-policy-modifying-external-accounts.html
The support is required for clusters, their backups and Atlas Data Lake.
3
votes
Andrey
shared this idea