EBS volume encryption settings need review

Request encryption for new EBS volumes and verify regional defaults and actual volume and snapshot encryption.

Description

EBS encryption protects data stored on a volume and snapshots made from it. Explicitly set encrypted: true for new volumes and check the KMS key and permissions you need.

New volumes are encrypted when EBS encryption by default is enabled in the Region. Volumes created from encrypted snapshots are encrypted too. Omitting the option or setting it to false therefore does not establish that the actual volume is unencrypted. Check the real state of existing volumes.

Potential impact

  • Data and snapshots of an actually unencrypted volume lack EBS encryption protection and may not meet organizational encryption-at-rest requirements.
  • Encryption does not replace operating-system or application access controls or TLS for application traffic.

Remediation

  • Review the new-volume encryption request, KMS key and permissions, regional defaults and source snapshot together.
  • Changing a flag cannot encrypt an existing unencrypted volume. Create a new encrypted volume using a snapshot or migrate the data, planning attachment changes, data consistency and downtime.
  • Verify actual volume and snapshot encryption, the KMS key and normal workload operation afterward.

Examples

Set instance_id to the actual instance ID and select an attachment device appropriate for that instance.

Configuration without an encryption request

yaml
---
- name: Creating EBS volume01
  amazon.aws.ec2_vol:
    instance: "{{ instance_id }}"
    encrypted: false
    volume_size: 50
    volume_type: gp2
    device_name: /dev/xvdf

This does not explicitly request encryption. If regional encryption defaults apply or the operation uses an existing volume, check its actual encryption state separately.

Request encryption for a new volume

yaml
- name: Creating EBS volume05
  amazon.aws.ec2_vol:
    instance: "{{ instance_id }}"
    encrypted: yes
    volume_size: 50
    volume_type: gp2
    device_name: /dev/xvdf

encrypted: yes requests encryption for a new volume. It does not automatically encrypt an already attached unencrypted volume.

References