Description
When creating an encrypted RDS or Aurora database, omitting KmsKeyId uses the default AWS managed KMS key. That key still encrypts the data; not selecting a customer managed key does not mean storage is plaintext.
A customer managed key may be needed when your organization must control key policies, lifecycle or separation between services.
Potential impact
- The default key may not meet requirements for independent key management or separation of permissions.
- Changing keys without accounting for service migration constraints can interrupt data access or recovery.
Remediation
- Where a customer managed key is required, set
StorageEncrypted: trueand an approvedKmsKeyId. - Grant the service and operators the necessary key permissions, and control key disablement and deletion.
- An existing encrypted RDS or Aurora database cannot switch keys merely by changing the template value. Plan a supported snapshot-copy and restore procedure and application cutover.
Examples
These are encryption excerpts for a new Aurora MySQL cluster. DatabaseKeyArn is an approved customer managed key ARN in the same Region; configure credentials, instances and networking separately.
Before
Resources:
AppDbCluster:
Type: AWS::RDS::DBCluster
Properties:
Engine: aurora-mysql
StorageEncrypted: true
Storage is encrypted with the default AWS managed key. This can be appropriate if it meets your organization’s requirements.
After
Resources:
AppDbCluster:
Type: AWS::RDS::DBCluster
Properties:
Engine: aurora-mysql
StorageEncrypted: true
KmsKeyId: !Ref DatabaseKeyArn
A customer managed key is selected for the new cluster. This is not a procedure for automatically migrating an existing cluster’s data to another key.