Default database KMS key usage

Check whether an encrypted database’s default KMS key meets your key-management requirements.

Description

When creating an encrypted RDS or Aurora database, omitting KmsKeyId uses the default AWS managed KMS key. That key still encrypts the data; not selecting a customer managed key does not mean storage is plaintext.

A customer managed key may be needed when your organization must control key policies, lifecycle or separation between services.

Potential impact

  • The default key may not meet requirements for independent key management or separation of permissions.
  • Changing keys without accounting for service migration constraints can interrupt data access or recovery.

Remediation

  • Where a customer managed key is required, set StorageEncrypted: true and an approved KmsKeyId.
  • Grant the service and operators the necessary key permissions, and control key disablement and deletion.
  • An existing encrypted RDS or Aurora database cannot switch keys merely by changing the template value. Plan a supported snapshot-copy and restore procedure and application cutover.

Examples

These are encryption excerpts for a new Aurora MySQL cluster. DatabaseKeyArn is an approved customer managed key ARN in the same Region; configure credentials, instances and networking separately.

Before

yaml
Resources:
  AppDbCluster:
    Type: AWS::RDS::DBCluster
    Properties:
      Engine: aurora-mysql
      StorageEncrypted: true

Storage is encrypted with the default AWS managed key. This can be appropriate if it meets your organization’s requirements.

After

yaml
Resources:
  AppDbCluster:
    Type: AWS::RDS::DBCluster
    Properties:
      Engine: aurora-mysql
      StorageEncrypted: true
      KmsKeyId: !Ref DatabaseKeyArn

A customer managed key is selected for the new cluster. This is not a procedure for automatically migrating an existing cluster’s data to another key.

References