12 ‐ Encrypt Boot volume with Custom managed keys - SanjeevOCI/Ocidocs GitHub Wiki

  1. Navigate to Burger Menu --> Storage --> Boot Volumes --> Select the Boot Volume --> Click on Encryption Key --> Assign

Vault_Creation_10

Vault_Creation_11

Vault_Creation_15

  1. The above error indicates that the KMS key doesn't has the right permissions. In order to assign the encryption key to the Boot Volume, we need to create a policy to allow the Block Storage to use keys in the compartment(computecompartment) where the vault is located.

Encryption key access policy_1

Encryption key access policy_2

Encryption key access policy_3

Encryption key access policy_4

  1. Now that the policy has been created, we are able to assign the Encryption keys to the Boot volume

Assign_Encryption_key

Boot Volume Encrypted