Encryption
UpCloud encrypts data at rest across its storage and database products. On some products, encryption is always on. On others, you enable it when you create the resource. In both cases, UpCloud generates and manages the encryption keys, and encryption and decryption happen transparently, with no configuration or key management on your side.
Encryption at rest by product
| Product | Encryption at rest | Algorithm | Details |
|---|---|---|---|
| Block Storage | Optional, enabled when the storage device is created | AES-256 | Block Storage encryption at rest |
| File Storage | Optional, enabled when the instance is created | AES-256 | File Storage encryption |
| Managed Object Storage | Always on | AES-256 | Full encryption |
| Managed Databases | Always on, for service instances and backups | LUKS2 aes-xts-plain64 with a 512-bit key for service volumes, AES-256 in CTR mode for backups | MySQL, PostgreSQL, OpenSearch, Valkey |
| Managed Kubernetes | Optional, per cluster, node group, or Persistent Volume | AES-256, using Block Storage encryption at rest | Encrypted clusters |
Encryption keys
Block Storage generates a random encryption key for each storage device. The keys themselves are stored encrypted. Backups, clones, and custom images created from an encrypted storage device are also encrypted.
Managed Databases generate a unique key for each service instance and volume. These keys are never reused and are disposed of when the instance is terminated, so upgrades, which replace the instances, also rotate the keys. Each backup file is encrypted with its own key, which is in turn encrypted with an RSA key pair generated for the service.
Using your own encryption keys
To keep the encryption keys under your own control:
- Block Storage: encrypt the storage device inside your Cloud Server with LUKS. See Encrypt a Block Storage device with LUKS. You can combine this with Block Storage encryption at rest.
- Managed Object Storage: send your own key with each request (SSE-C), or encrypt files on your computer before you upload them. See Encrypt Object Storage data with your own keys.
For other products, the encryption keys are managed by UpCloud, and customer-managed keys are not supported.
If you lose keys you manage yourself, you lose access to the data encrypted with them. Store copies of your keys and passphrases separately from the data they protect.
