RDS storage encryption settings need review

Explicitly configure RDS encryption at rest, and migrate existing unencrypted instances through a supported copy and restore workflow.

Description

RDS encryption at rest protects database storage and associated backups and snapshots. For a new ordinary RDS instance, explicitly request storage_encrypted: true and configure the KMS key and permissions you need. Aurora manages encryption at the cluster level instead.

For existing resources and snapshot restores, check the encryption state and behavior of that resource and operation. A key value in a playbook does not establish that an existing database is encrypted.

Potential impact

  • An actually unencrypted database and its associated backups lack the protection of encryption at rest and may not meet organizational encryption requirements.
  • Encryption at rest still requires separate database authentication, access permissions and encryption in transit.

Remediation

  • Configure storage_encrypted: true and the required KMS key and permissions for new instances. For Aurora, review cluster settings.
  • A flag change cannot encrypt an existing unencrypted instance. Use a supported encrypted snapshot copy and restore workflow, planning data consistency, connection cutover and downtime.
  • Verify the real instance's StorageEncrypted value, KMS key, backups and replicas afterward. Check database access controls and TLS as well.

Examples

Supply the actual username, securely managed password, storage size and an instance class supported for the engine and Region. Configure networking and access controls separately.

New instance without an encryption request

yaml
---
- name: foo
  community.aws.rds_instance:
    id: test-encrypted-db
    state: present
    engine: mariadb
    storage_encrypted: false
    db_instance_class: "{{ db_instance_class }}"
    username: "{{ username }}"
    password: "{{ password }}"
    allocated_storage: "{{ allocated_storage }}"

This does not request storage encryption when creating a new MariaDB instance. If an instance with the identifier already exists, check its actual encryption state.

New instance with an encryption request

yaml
- name: foo
  community.aws.rds_instance:
    id: test-encrypted-db
    state: present
    engine: mariadb
    storage_encrypted: true
    db_instance_class: "{{ db_instance_class }}"
    username: "{{ username }}"
    password: "{{ password }}"
    allocated_storage: "{{ allocated_storage }}"

This requests encryption at rest for a new instance. Applying only this setting with the identifier of an existing unencrypted instance is not an encryption migration procedure.

References