

AWS KMS 降價
source link: https://blog.gslin.org/archives/2024/04/30/11775/aws-kms-%e9%99%8d%e5%83%b9/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

AWS KMS 降價
看到 AWS KMS 的公告:「AWS KMS announces more flexible automatic key rotation」。
第一個是增加了 rotation 的彈性,可以設定日期,不過 7 years (2560 days) 是怎麼算出來的?(某種風險公式?):
You can now customize the frequency of rotation period between 90 days to 7 years (2560 days) as well as invoke key rotation on demand for customer managed KMS keys.
另外一個是降價,看起來是 rotate 第三次以後就不收費?對於有在 rotation 的單位來說是個降價... (如果沒在 rotate 的就 XDDD)
We’re also introducing new pricing for KMS automatic key rotation. Previously, each rotation of a KMS key added $1/month per rotation to a KMS customer managed key. Now, for KMS keys that you rotate automatically or on demand, the first and second rotation of the key adds $1/month (prorated hourly) in cost, but this price increase is capped at the second rotation, and all rotations after your second rotation are not billed. For customers that have keys with 3 or more rotations, all of these keys will see a price reduction to $3/month (prorated) starting the first week of May 2024.
這也算是鼓勵拉高 rotation 的次數吧?
Related
AWS KMS 推出 Multi-region keys
這應該是 AWS 被許多大客戶敲碗許久的功能之一,AWS KMS 支援 global key:「Encrypt global data client-side with AWS KMS multi-Region keys」。 以前不支援這個功能時,在加密儲存跨區域的資料會有兩種作法,以 us-east-1 與 ap-northeast-1 為例子來說: 第一種是透過 replication 的概念,檔案內容從 us-east-1 解開後,透過 TLS 傳到 ap-northeast-1 再加密,所以不同區的密文內容是不同的。 第二種是自己抽象一層 AES key,檔案內容都用這把 AES key 加解密,而這把 AES key 則透過不同區的 AWS KMS 保護,但這樣做又要自己搞 key rotation,另外還可能會有 auditing 的問題... 現在 AWS KMS 直接支援就省事很多了: 文章裡面是拿…
June 18, 2021In "AWS"
AWS KMS 可以在 VPC 內直接存取了
AWS Key Management Service 宣布支援 AWS PrivateLink Endpoint 了:「How to Connect Directly to AWS Key Management Service from Amazon VPC by Using an AWS PrivateLink Endpoint」。先前需要透過 Internet 流量存取 (透過 NAT、Proxy 之類的服務),現在則是可以接到 VPC 內直接用了: Previously, applications running inside a VPC required internet access to connect to AWS KMS. This meant managing…
January 23, 2018In "AWS"
DynamoDB 可以透過 KMS 加密了...
AWS 讓 DynamoDB 可以透過 KMS 加密了:「New – Encryption at Rest for DynamoDB」。 You simply enable encryption when you create a new table and DynamoDB takes care of the rest. Your data (tables, local secondary indexes, and global secondary indexes) will be encrypted using AES-256 and a service-default AWS Key Management…
February 10, 2018In "AWS"
Author Gea-Suan LinPosted on April 30, 2024Categories AWS, Cloud, Computer, Murmuring, Network, Security, ServiceTags amazon, aws, cloud, kms, pricing, service
Leave a Reply
Your email address will not be published. Required fields are marked *
Comment *
Name *
Email *
Website
Notify me of follow-up comments by email.
Notify me of new posts by email.
To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Learn More)
Post navigation
Recommend
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK