Skip to main content

ES Node Config Disk Encryption

ID: rule:aliyun:elasticsearch-instance-enabled-node-config-disk-encryption
Severity: medium

Description

Ensures Elasticsearch elastic node configurations have disk encryption enabled.

Reason for Violation

Elastic nodes can store sensitive transient data.

Recommendation

Enable disk encryption for all node configurations in the ES instance.

Resource Types

  • ALIYUN::ElasticSearch::Instance