EFS encryption at rest settings need review

Enable encryption at rest for new EFS file systems and migrate existing unencrypted file systems to an encrypted destination.

Description

EFS encryption at rest protects data stored in the file system. Explicitly set encrypt: true when creating a file system and check the required KMS key and permissions. Do not confuse the EFS console's default encryption setting with options used for API creation.

A file system's encryption setting cannot be changed after creation. Existing unencrypted file systems require migration to a new encrypted file system; changing only a playbook option does not complete that work.

Potential impact

  • Files on an actually unencrypted EFS file system lack encryption-at-rest protection and may not meet organizational encryption requirements.
  • Encryption at rest does not replace file access permissions or TLS for mount connections.

Remediation

  • Set encrypt: true for new file systems and configure the KMS key and permissions. For existing file systems, check their actual encryption state first.
  • Use a supported replication or data-migration procedure to move unencrypted EFS data to a new encrypted file system. Plan mount paths, application cutover, data consistency and downtime.
  • Verify encryption and file access afterward. Check backup and restore encryption, TLS mounts, security groups and access policies as well.

Examples

Replace the subnet and security group IDs with actual resources and prepare the required connectivity permissions.

New file system without an encryption request

yaml
---
- name: foo
  community.aws.efs:
    state: present
    name: myTestEFS
    encrypt: false
    tags:
      Name: myTestNameTag
      purpose: file-storage
    targets:
      - subnet_id: subnet-748c5d03
        security_groups: ["sg-1a2b3c4d"]

This does not request encryption at rest when creating a file system. When managing an existing file system, check its actual encryption state.

New file system with an encryption request

yaml
- name: foo
  community.aws.efs:
    state: present
    name: myTestEFS
    encrypt: true
    tags:
      Name: myTestNameTag
      purpose: file-storage
    targets:
      - subnet_id: subnet-748c5d03
        security_groups: ["sg-1a2b3c4d"]

encrypt: true requests encryption for a new file system. If myTestEFS already exists without encryption, applying the option to that name does not encrypt it; migrate the data to a separate encrypted destination.

References