DAX cluster encryption at rest is disabled

Encrypt the cache data DAX persists to disk, and migrate existing unencrypted clusters to new encrypted clusters.

Description

DAX writes data to disk while propagating changes between nodes. Encryption at rest adds protection against unauthorized access to this underlying storage. Check the DAX cluster separately from encryption on its DynamoDB tables.

Potential impact

  • Unencrypted cache data lacks this additional protection and may not meet organizational data-protection requirements.
  • An unplanned cluster replacement can interrupt application connections or increase DynamoDB load while the cache fills.

Remediation

  • Set SSESpecification.SSEEnabled: true on new clusters and select a node type that supports encryption. The dax.r3.* family does not support it.
  • Encryption cannot be changed after cluster creation. Prepare a new encrypted cluster with the required name and networking, switch application connections, and verify operation.
  • DAX uses the service's AWS managed key; customer-specified KMS keys are not supported. Manage IAM permissions, network access and encryption in transit separately.

Examples

These are alternatives for a new cluster. Provide a node type supported in the Region, an actual DAX role ARN, and appropriate subnets and security groups. A single node is not a highly available configuration; replacement requires planning for names and connection cutover.

Encryption at rest disabled

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: "Create a DAX cluster"
Resources:
  daxCluster:
    Type: AWS::DAX::Cluster
    Properties:
      SSESpecification:
        SSEEnabled: false
      ClusterName: "MyDAXCluster"
      NodeType: "dax.t3.small"
      ReplicationFactor: 1
      IAMRoleARN: "arn:aws:iam::111122223333:role/DaxAccess"
      Description: "DAX cluster created with CloudFormation"

Encryption of data that DAX persists to disk is disabled.

Encryption at rest enabled

yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: "Create a DAX cluster"
Resources:
  daxCluster:
    Type: AWS::DAX::Cluster
    Properties:
      SSESpecification:
        SSEEnabled: true
      ClusterName: "MyDAXCluster"
      NodeType: "dax.t3.small"
      ReplicationFactor: 1
      IAMRoleARN: "arn:aws:iam::111122223333:role/DaxAccess"
      Description: "DAX cluster created with CloudFormation"

This enables encryption for a new cluster. It does not change encryption while retaining the existing cluster.

References