Description
An encrypted EBS volume without KmsKeyId uses the default EBS KMS key configured in that Region. That default can also be a customer managed key; omitting the property does not mean plaintext storage.
Potential impact
If the default key does not meet the volume’s access-control or audit requirements, it may fail the organization’s key-management policy.
Remediation
When a specific key is required, set Encrypted: true and specify a KmsKeyId in the same Region, then check permissions. Changing an existing volume’s key requires creating a new volume through a snapshot.
Examples
The examples compare the default key with an explicitly selected key at volume creation. MyKmsKey must refer to an actual key defined separately.
Before
yaml
Resources:
DataVolume:
Type: AWS::EC2::Volume
Properties:
Size: 100
Encrypted: true
AvailabilityZone: us-west-1a
After
yaml
Resources:
DataVolume:
Type: AWS::EC2::Volume
Properties:
Size: 100
Encrypted: true
AvailabilityZone: us-west-1a
KmsKeyId: !Ref MyKmsKey