Description
Kinesis server-side encryption protects records stored in the stream. Where encryption is required, explicitly set encryption_state: enabled, encryption_type: KMS and a valid key_id, and verify the actual stream state. Omitting an option while managing an existing stream does not itself disable its encryption.
Encryption applies to records arriving after activation. It does not retroactively encrypt records previously stored without encryption. Stream access permissions and transport protection are still required separately.
Potential impact
- If server-side encryption is actually disabled, newly stored sensitive records may not meet encryption-at-rest requirements.
- Incorrect key permissions or configuration can disrupt producers or consumers. Older unencrypted records still need separate consideration after encryption is enabled.
Remediation
- Check the stream's actual encryption state and explicitly configure the required type, state and key.
- Give producers and consumers the KMS permissions needed for their operations, and restrict unnecessary key use.
- After the change completes, verify stream status, encryption of new records and successful writes and reads. Review retention and handling of older records, stream permissions and transport protection as well.
Examples
Before
- name: Encrypt Kinesis Stream test-stream
community.aws.kinesis_stream:
name: test-stream
state: present
shards: 1
encryption_state: disabled
encryption_type: KMS
key_id: alias/aws/kinesis
wait: yes
wait_timeout: 600
encryption_state: disabled requests disabling encryption. Specifying an encryption type and key alongside it does not turn that request into activation.
After
- name: Encrypt Kinesis Stream test-stream
community.aws.kinesis_stream:
name: test-stream
state: present
shards: 1
encryption_state: enabled
encryption_type: KMS
key_id: alias/aws/kinesis
wait: yes
wait_timeout: 600
This requests encryption using alias/aws/kinesis, the alias for the AWS managed Kinesis key. Check the required permissions and verify protection for new records after activation. Existing records are not retroactively encrypted.