Description
EFS encryption at rest protects data stored in the file system. Explicitly set encrypt: true when creating a file system and check the required KMS key and permissions. Do not confuse the EFS console's default encryption setting with options used for API creation.
A file system's encryption setting cannot be changed after creation. Existing unencrypted file systems require migration to a new encrypted file system; changing only a playbook option does not complete that work.
Potential impact
- Files on an actually unencrypted EFS file system lack encryption-at-rest protection and may not meet organizational encryption requirements.
- Encryption at rest does not replace file access permissions or TLS for mount connections.
Remediation
- Set
encrypt: truefor new file systems and configure the KMS key and permissions. For existing file systems, check their actual encryption state first. - Use a supported replication or data-migration procedure to move unencrypted EFS data to a new encrypted file system. Plan mount paths, application cutover, data consistency and downtime.
- Verify encryption and file access afterward. Check backup and restore encryption, TLS mounts, security groups and access policies as well.
Examples
Replace the subnet and security group IDs with actual resources and prepare the required connectivity permissions.
New file system without an encryption request
---
- name: foo
community.aws.efs:
state: present
name: myTestEFS
encrypt: false
tags:
Name: myTestNameTag
purpose: file-storage
targets:
- subnet_id: subnet-748c5d03
security_groups: ["sg-1a2b3c4d"]
This does not request encryption at rest when creating a file system. When managing an existing file system, check its actual encryption state.
New file system with an encryption request
- name: foo
community.aws.efs:
state: present
name: myTestEFS
encrypt: true
tags:
Name: myTestNameTag
purpose: file-storage
targets:
- subnet_id: subnet-748c5d03
security_groups: ["sg-1a2b3c4d"]
encrypt: true requests encryption for a new file system. If myTestEFS already exists without encryption, applying the option to that name does not encrypt it; migrate the data to a separate encrypted destination.