Description
RDS encryption at rest protects database storage and associated backups and snapshots. For a new ordinary RDS instance, explicitly request storage_encrypted: true and configure the KMS key and permissions you need. Aurora manages encryption at the cluster level instead.
For existing resources and snapshot restores, check the encryption state and behavior of that resource and operation. A key value in a playbook does not establish that an existing database is encrypted.
Potential impact
- An actually unencrypted database and its associated backups lack the protection of encryption at rest and may not meet organizational encryption requirements.
- Encryption at rest still requires separate database authentication, access permissions and encryption in transit.
Remediation
- Configure
storage_encrypted: trueand the required KMS key and permissions for new instances. For Aurora, review cluster settings. - A flag change cannot encrypt an existing unencrypted instance. Use a supported encrypted snapshot copy and restore workflow, planning data consistency, connection cutover and downtime.
- Verify the real instance's
StorageEncryptedvalue, KMS key, backups and replicas afterward. Check database access controls and TLS as well.
Examples
Supply the actual username, securely managed password, storage size and an instance class supported for the engine and Region. Configure networking and access controls separately.
New instance without an encryption request
---
- name: foo
community.aws.rds_instance:
id: test-encrypted-db
state: present
engine: mariadb
storage_encrypted: false
db_instance_class: "{{ db_instance_class }}"
username: "{{ username }}"
password: "{{ password }}"
allocated_storage: "{{ allocated_storage }}"
This does not request storage encryption when creating a new MariaDB instance. If an instance with the identifier already exists, check its actual encryption state.
New instance with an encryption request
- name: foo
community.aws.rds_instance:
id: test-encrypted-db
state: present
engine: mariadb
storage_encrypted: true
db_instance_class: "{{ db_instance_class }}"
username: "{{ username }}"
password: "{{ password }}"
allocated_storage: "{{ allocated_storage }}"
This requests encryption at rest for a new instance. Applying only this setting with the identifier of an existing unencrypted instance is not an encryption migration procedure.