There is currently no option to enable the encryption of EBS volumes created by this plugin. This makes security teams unhappy.
Adding an option to encrypt EBS volumes with either the aws/ebs KMS key or a customer managed key would make this better, and doesn't sound like it should be too difficult to implement.
I have considered setting account-wide default encryption to mitigate this, but that causes problems when building AMIs to be shared across multiple accounts
There is currently no option to enable the encryption of EBS volumes created by this plugin. This makes security teams unhappy.
Adding an option to encrypt EBS volumes with either the aws/ebs KMS key or a customer managed key would make this better, and doesn't sound like it should be too difficult to implement.
I have considered setting account-wide default encryption to mitigate this, but that causes problems when building AMIs to be shared across multiple accounts