KMS key availability needs review

Check the availability and deletion plans of KMS keys used by your services.

Description

A disabled KMS key or a key actually pending deletion can cause cryptographic operations that require it to fail. Encryption at rest does not prevent a service outage when its key is unavailable.

PendingWindowInDays sets the waiting period when CloudFormation deletes the key. Setting this property does not itself schedule deletion or disable the key. Check the actual key state and dependent services.

Potential impact

  • Data reads, resource creation or backup recovery that require the key can fail.
  • Once the key is deleted, data that can only be decrypted with it may be unrecoverable.

Remediation

  • Check key state and permissions, investigate why a key was disabled, and enable it when it is still needed.
  • If deletion is scheduled for a required key, cancel deletion in KMS and enable the key again. Adding a key back to the template does not restore the original key.
  • Before retiring a key, verify that existing data and backups no longer depend on it for decryption.

Examples

These examples compare key availability. Configure application permissions to use the key separately.

Before

yaml
Resources:
  AppKey:
    Type: AWS::KMS::Key
    Properties:
      Enabled: false
      PendingWindowInDays: 7
      KeyPolicy:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              AWS: !Sub arn:aws:iam::${AWS::AccountId}:root
            Action: kms:*
            Resource: "*"

Enabled: false prevents cryptographic use of the key. PendingWindowInDays: 7 specifies a waiting period for deletion; it does not establish that deletion is currently pending.

After

yaml
Resources:
  AppKey:
    Type: AWS::KMS::Key
    Properties:
      Enabled: true
      KeyPolicy:
        Version: '2012-10-17'
        Statement:
          - Effect: Allow
            Principal:
              AWS: !Sub arn:aws:iam::${AWS::AccountId}:root
            Action: kms:*
            Resource: "*"

The key is enabled. Omitting the waiting period does not prevent deletion, so manage the actual key state and deletion permissions.

References