Review rotation settings for customer-managed KMS keys

Use rotation appropriate to the key type and manage access permissions separately.

Description

KMS key rotation reduces prolonged use of the same key material. Automatic rotation applies to supported key types and origins. The key ARN and access policy remain in place; rotation alone does not re-encrypt existing data or revoke a compromised principal’s permissions.

Potential impact

  • Required key-material lifetime controls may not be met without the appropriate rotation process.
  • Treating rotation as permission revocation or data re-encryption can leave incident-response actions incomplete.

Remediation

  • Check the key type and origin, and set enable_key_rotation: true where required for a customer-managed key that supports automatic rotation. Provide an appropriate replacement process for unsupported key types.
  • Manage the key policy and uses, and revoke a compromised principal’s permissions separately. Verify the actual rotation status and schedule.

Examples

These examples compare settings for a key that supports automatic rotation. Supply a reviewed, valid JSON policy in kms_key_policy_json that avoids lockout and excessive permissions. The legacy community.aws.aws_kms name currently redirects to amazon.aws.kms_key.

Before

yaml
- name: Update the KMS key policy
  community.aws.aws_kms:
    alias: my-kms-key
    policy: "{{ kms_key_policy_json }}"
    state: present
    enabled: true

After

yaml
- name: Update the KMS key policy
  community.aws.aws_kms:
    alias: my-kms-key
    policy: "{{ kms_key_policy_json }}"
    state: present
    enabled: true
    enable_key_rotation: true

Explanation:

  • Before: Automatic rotation is not declared. Check the actual key’s rotation status.
  • After: Automatic rotation is enabled. KMS retains older key material needed to decrypt existing data.

References