S3 bucket configuration requests removal of default encryption

Deleting an S3 default encryption configuration does not disable encryption for new uploads. Check that the required encryption method and key remain configured.

Description

encryption: none requests deletion of the bucket's default encryption configuration. On current AWS S3, DeleteBucketEncryption resets the default to SSE-S3 using S3-managed keys. Since January 5, 2023, new object uploads are automatically encrypted on the server, and this baseline protection cannot be disabled.

Removing an SSE-KMS default can mean that subsequent uploads using the default no longer use the KMS key management required by your organization. Protection for new uploads is separate from the state of existing objects. Changing the default does not encrypt previously unencrypted objects.

Potential impact

  • Reverting from SSE-KMS to SSE-S3 preserves encryption but can remove the required key and key-policy controls from new uploads.
  • Objects that do not meet encryption-at-rest requirements can remain if their individual encryption state is not checked. Encryption does not resolve excessive read permissions or public access.

Remediation

  • Define the encryption method and key-management requirements, then explicitly set AES256 or aws:kms through a module compatible with current AWS behavior. Configure encryption_key_id and key permissions when a particular key is required.
  • Verify the actual default algorithm and key after applying the change, and test uploads and downloads. An older module's failure does not prove that an already-requested configuration change was rolled back.
  • Check encryption on individual objects. If older unencrypted objects need protection, plan to copy them with encryption, using individual copy operations or S3 Batch Operations. Maintain access policies and protection in transit as well.

Examples

Replace the bucket name with the bucket you manage and use a module version compatible with current AWS behavior. These examples configure defaults; they do not change the encryption of existing objects.

Request removal of the default encryption configuration

yaml
- name: Create a simple s3 bucket
  amazon.aws.s3_bucket:
    name: mys3bucket
    state: present
    encryption: "none"

On current AWS S3, the default returns to SSE-S3. This is not a way to disable encryption for new uploads.

Request SSE-KMS default encryption

yaml
- name: Create a simple s3 bucket
  amazon.aws.s3_bucket:
    name: mys3bucket
    state: present
    encryption: aws:kms

This requests SSE-KMS as the default for new uploads. It does not select a particular customer-managed key because encryption_key_id is absent. Check the required key and the permissions of uploaders and downloaders separately.

References