Description
encryption: none requests deletion of the bucket's default encryption configuration. On current AWS S3, DeleteBucketEncryption resets the default to SSE-S3 using S3-managed keys. Since January 5, 2023, new object uploads are automatically encrypted on the server, and this baseline protection cannot be disabled.
Removing an SSE-KMS default can mean that subsequent uploads using the default no longer use the KMS key management required by your organization. Protection for new uploads is separate from the state of existing objects. Changing the default does not encrypt previously unencrypted objects.
Potential impact
- Reverting from SSE-KMS to SSE-S3 preserves encryption but can remove the required key and key-policy controls from new uploads.
- Objects that do not meet encryption-at-rest requirements can remain if their individual encryption state is not checked. Encryption does not resolve excessive read permissions or public access.
Remediation
- Define the encryption method and key-management requirements, then explicitly set
AES256oraws:kmsthrough a module compatible with current AWS behavior. Configureencryption_key_idand key permissions when a particular key is required. - Verify the actual default algorithm and key after applying the change, and test uploads and downloads. An older module's failure does not prove that an already-requested configuration change was rolled back.
- Check encryption on individual objects. If older unencrypted objects need protection, plan to copy them with encryption, using individual copy operations or S3 Batch Operations. Maintain access policies and protection in transit as well.
Examples
Replace the bucket name with the bucket you manage and use a module version compatible with current AWS behavior. These examples configure defaults; they do not change the encryption of existing objects.
Request removal of the default encryption configuration
- name: Create a simple s3 bucket
amazon.aws.s3_bucket:
name: mys3bucket
state: present
encryption: "none"
On current AWS S3, the default returns to SSE-S3. This is not a way to disable encryption for new uploads.
Request SSE-KMS default encryption
- name: Create a simple s3 bucket
amazon.aws.s3_bucket:
name: mys3bucket
state: present
encryption: aws:kms
This requests SSE-KMS as the default for new uploads. It does not select a particular customer-managed key because encryption_key_id is absent. Check the required key and the permissions of uploaders and downloaders separately.