Description
KMS key rotation reduces prolonged use of the same key material. Automatic rotation applies to supported key types and origins. The key ARN and access policy remain in place; rotation alone does not re-encrypt existing data or revoke a compromised principal’s permissions.
Potential impact
- Required key-material lifetime controls may not be met without the appropriate rotation process.
- Treating rotation as permission revocation or data re-encryption can leave incident-response actions incomplete.
Remediation
- Check the key type and origin, and set enable_key_rotation: true where required for a customer-managed key that supports automatic rotation. Provide an appropriate replacement process for unsupported key types.
- Manage the key policy and uses, and revoke a compromised principal’s permissions separately. Verify the actual rotation status and schedule.
Examples
These examples compare settings for a key that supports automatic rotation. Supply a reviewed, valid JSON policy in kms_key_policy_json that avoids lockout and excessive permissions. The legacy community.aws.aws_kms name currently redirects to amazon.aws.kms_key.
Before
yaml
- name: Update the KMS key policy
community.aws.aws_kms:
alias: my-kms-key
policy: "{{ kms_key_policy_json }}"
state: present
enabled: true
After
yaml
- name: Update the KMS key policy
community.aws.aws_kms:
alias: my-kms-key
policy: "{{ kms_key_policy_json }}"
state: present
enabled: true
enable_key_rotation: true
Explanation:
- Before: Automatic rotation is not declared. Check the actual key’s rotation status.
- After: Automatic rotation is enabled. KMS retains older key material needed to decrypt existing data.