In this case, usually the infrastructure provider owns the keys, and if not, they would have easy access to them. So I don't see how encrypted disk really solves anything besides accidental leakage to a peer infra user, or someone sneaking into the datacenter and physically removing the disks.