This work focuses on enhancing support for encrypted AMIs including both API and Console enhancements. Special care was taken to also support AMIs encrypted by KMS keys shared with an organization via RAM. The service now also supports cross- region encrypted AMI distribution.
I cannot change the encryption like I can with EC2 on the root volume. I see that it says you can in the UI (AMI root) but this is only the secondary volume, not what it says it is.
This work focuses on enhancing support for encrypted AMIs including both API and Console enhancements. Special care was taken to also support AMIs encrypted by KMS keys shared with an organization via RAM. The service now also supports cross- region encrypted AMI distribution.