1) Do we create the EBS volume from EBS Snapshot or AMI ?

2) Do we just detach the unencrypted EBS root volume and attached the encrypted EBS volume, created from the encrypted EBS snapshot ?

It all depends on what you are trying to do and which volume you are changing.

If it is the boot volume you will need to go down the road of building and AMI from the snapshot

If you are retroactively converting a secondly volume to encrypted.  You can remove one vol and mount the other, then use the normal Linux or Windows tools to tweak the OS to recognise the new volumes.


