Description
EBS encryption protects data stored on a volume and snapshots made from it. Explicitly set encrypted: true for new volumes and check the KMS key and permissions you need.
New volumes are encrypted when EBS encryption by default is enabled in the Region. Volumes created from encrypted snapshots are encrypted too. Omitting the option or setting it to false therefore does not establish that the actual volume is unencrypted. Check the real state of existing volumes.
Potential impact
- Data and snapshots of an actually unencrypted volume lack EBS encryption protection and may not meet organizational encryption-at-rest requirements.
- Encryption does not replace operating-system or application access controls or TLS for application traffic.
Remediation
- Review the new-volume encryption request, KMS key and permissions, regional defaults and source snapshot together.
- Changing a flag cannot encrypt an existing unencrypted volume. Create a new encrypted volume using a snapshot or migrate the data, planning attachment changes, data consistency and downtime.
- Verify actual volume and snapshot encryption, the KMS key and normal workload operation afterward.
Examples
Set instance_id to the actual instance ID and select an attachment device appropriate for that instance.
Configuration without an encryption request
---
- name: Creating EBS volume01
amazon.aws.ec2_vol:
instance: "{{ instance_id }}"
encrypted: false
volume_size: 50
volume_type: gp2
device_name: /dev/xvdf
This does not explicitly request encryption. If regional encryption defaults apply or the operation uses an existing volume, check its actual encryption state separately.
Request encryption for a new volume
- name: Creating EBS volume05
amazon.aws.ec2_vol:
instance: "{{ instance_id }}"
encrypted: yes
volume_size: 50
volume_type: gp2
device_name: /dev/xvdf
encrypted: yes requests encryption for a new volume. It does not automatically encrypt an already attached unencrypted volume.