It's just like encrypting EBS/block storage on AWS and clouds. You generate the keys and those keys are with the cloud provider nevertheless so it's not encrypted at all pretty much for all practical purposes.
But it's good enough for compliance work. :)
Yeah, that's about it. It's just plain unencrypted otherwise. :)