Bring Your Own Key to Existing Elastic Cloud Deployments
Elastic, Thursday, October 1st, 2026
Bring your own key for existing Elastic Cloud Hosted deployments is now GA, adding customer-managed keys without redeploying.
Elastic has made bring your own key (BYOK) for existing deployments generally available on Elastic Cloud Hosted.
Customers can add a customer-managed encryption key from AWS KMS, Azure Key Vault or Google Cloud KMS to a running deployment via the console or API, with the deployment remaining accessible, whereas previously keys could only be set at creation, forcing a migration when key management requirements arrived later.
The post explains how the in-place transition works and what to consider before encrypting production deployments.