Kinesis encryption settings need review

Encrypt new records stored in Kinesis with KMS, and verify key permissions and successful writes and reads.

Description

Kinesis server-side encryption protects records stored in the stream. Where encryption is required, explicitly set encryption_state: enabled, encryption_type: KMS and a valid key_id, and verify the actual stream state. Omitting an option while managing an existing stream does not itself disable its encryption.

Encryption applies to records arriving after activation. It does not retroactively encrypt records previously stored without encryption. Stream access permissions and transport protection are still required separately.

Potential impact

  • If server-side encryption is actually disabled, newly stored sensitive records may not meet encryption-at-rest requirements.
  • Incorrect key permissions or configuration can disrupt producers or consumers. Older unencrypted records still need separate consideration after encryption is enabled.

Remediation

  • Check the stream's actual encryption state and explicitly configure the required type, state and key.
  • Give producers and consumers the KMS permissions needed for their operations, and restrict unnecessary key use.
  • After the change completes, verify stream status, encryption of new records and successful writes and reads. Review retention and handling of older records, stream permissions and transport protection as well.

Examples

Before

yaml
- name: Encrypt Kinesis Stream test-stream
  community.aws.kinesis_stream:
    name: test-stream
    state: present
    shards: 1
    encryption_state: disabled
    encryption_type: KMS
    key_id: alias/aws/kinesis
    wait: yes
    wait_timeout: 600

encryption_state: disabled requests disabling encryption. Specifying an encryption type and key alongside it does not turn that request into activation.

After

yaml
- name: Encrypt Kinesis Stream test-stream
  community.aws.kinesis_stream:
    name: test-stream
    state: present
    shards: 1
    encryption_state: enabled
    encryption_type: KMS
    key_id: alias/aws/kinesis
    wait: yes
    wait_timeout: 600

This requests encryption using alias/aws/kinesis, the alias for the AWS managed Kinesis key. Check the required permissions and verify protection for new records after activation. Existing records are not retroactively encrypted.

References