Description
EBS encryption protects volume data and associated snapshots. Request encryption with Encrypted: true for new volumes and select the required KMS key. Account and Region defaults and source snapshots also affect the result, so false or omission alone does not establish that a deployed volume is unencrypted.
Potential impact
- Actually unencrypted volumes and snapshots lack this additional protection and may not meet data-protection requirements.
- Removing required key permissions or replacing a volume without migrating its data can disrupt application access and recovery.
Remediation
- Verify encryption and keys on actual volumes and snapshots. Explicitly request the required encryption for new volumes and review KMS permissions.
- Migrate an existing unencrypted volume through a supported process, such as creating a new volume from an encrypted copy of a consistent snapshot. CloudFormation does not support updating an existing volume's
Encryptedproperty. - Plan backups, attachment of the new volume, data verification and service interruption. Enabling encryption by default does not retroactively encrypt existing volumes or snapshots.
Examples
These alternatives create a new empty volume. Select the same Availability Zone as the instance that will use it. Data copying and volume attachment are not included.
Encryption not requested
AWSTemplateFormatVersion: "2010-09-09"
Description: Volume
Parameters:
VolumeAvailabilityZone:
Type: AWS::EC2::AvailabilityZone::Name
Resources:
NewVolume:
Type: AWS::EC2::Volume
Properties:
Size: 100
Encrypted: false
AvailabilityZone: !Ref VolumeAvailabilityZone
Tags:
- Key: MyTag
Value: TagValue
DeletionPolicy: Snapshot
An unencrypted volume can be created if encryption by default is off. Verify the actual result.
Encryption requested
AWSTemplateFormatVersion: "2010-09-09"
Description: Volume
Parameters:
VolumeAvailabilityZone:
Type: AWS::EC2::AvailabilityZone::Name
Resources:
NewVolume:
Type: AWS::EC2::Volume
Properties:
Size: 100
Encrypted: true
AvailabilityZone: !Ref VolumeAvailabilityZone
Tags:
- Key: MyTag
Value: TagValue
DeletionPolicy: Snapshot
This encrypts the new volume with the default KMS key. Specify an approved KmsKeyId if a different key is required. DeletionPolicy: Snapshot retains a snapshot on stack deletion; it does not migrate data.