Adding a KMS Key for Use on the Instaclustr Platform using Run in Instaclustr’s Account (RIIA) Provisioning

Instaclustr supports the creation of clusters in our provider account, which has EBS and S3 storage encrypted at rest using customer supplied KMS Keys. These instructions outline how to create the KMS Keys, and add them to the Instaclustr Platform. 

In your AWS account:

  1. Go to key management service and click on Create a Key
    Press the Create a Key button on the AWS Key Management Service home page
  2. Follow the AWS wizard to create an AWS Encryption Key in the data centre’s intended region. Make sure to add the Instaclustr Production AWS account. As seen in the example image below, do this by adding the ID: 624537489435
    Add the Instaclustr account to your key

Once you have created the key in your AWS account, go the Instaclustr console,

  1. Navigate to Cluster Resources -> Encryption Keys by clicking on the gear icon at the top right hand corner.
    Select the cluster resources button.
  2. You’ll need the AWS key’s ARN, found in the key’s details after key creation.
    Select the AWS Key's ARN
  3. The alias will identify this key in other parts of the Instaclustr console. Add the alias for your key, the AWS key’s ARN, and set the Provider Account to INSTACLUSTR. Once you have done this, click on Add Key to add the key to your account.
    Fill the text fields to add an encryption key onto the Instaclustr console
  4. Once the key is added to your account, it will show up in the table.
  5. Use the Validate button to check the validity of the key before cluster creation. For Multi-Region keys, the Validate button updates the list of regions that key is available in.
    Press the Validate button to check the regions associated with that particular key
  6. When you Create a Cluster or Add a Data Centre to an existing cluster, you will now have the option to enable EBS encryption.

For more information regarding Amazon’s encryption service see:

Further Questions

We are available to provide additional information and guide you through this process. Please contact Instaclustr Support or raise a new ticket.

By Instaclustr Support
Need Support?
Experiencing difficulties on the website or console?
Already have an account?
Need help with your cluster?
Contact Support
Why sign up?
To experience the ease of creating and managing clusters via the Instaclustr Console
Spin up a cluster in minutes