An in-use KMS key is disabled or pending deletion

Keep KMS keys available while operational resources depend on them.

Description

Disabling or scheduling deletion of a customer managed KMS key prevents cryptographic use of that key. Distinguish keys needed by operational resources from keys intentionally taken out of service.

Potential impact

Dependent data access or cryptographic operations can fail and interrupt services. Final key deletion can make data encrypted with that key unrecoverable.

Remediation

Keep required keys enabled and migrate dependent resources before deletion. Re-enable a required key after cancelling its deletion. Do not automatically reactivate keys intentionally disabled for retirement or incident response.

Examples

The example enables the existing my-kms-key after confirming it is needed. It does not demonstrate a key-policy change.

Before

yaml
- name: Set the state of an existing KMS key
  amazon.aws.kms_key:
    alias: my-kms-key
    state: present
    enabled: false

After

yaml
- name: Set the state of an existing KMS key
  amazon.aws.kms_key:
    alias: my-kms-key
    state: present
    enabled: true

References