Description
EKS encrypts the disks storing etcd data for every cluster. Kubernetes 1.28 and later also use default envelope encryption for all Kubernetes API data with an AWS-owned key. Absence of EncryptionConfig therefore does not establish that cluster data is stored in plaintext.
Configure a customer-managed KMS key when you must control its policy and lifecycle. This setting is separate from encryption of data on nodes or EBS volumes.
Potential impact
A default key may not satisfy an organization’s key-control requirements where a customer-managed key is required. Conversely, deleting an active key or removing required permissions can interrupt cluster operation and data access. Encryption does not replace Kubernetes access controls.
Remediation
Check the cluster version and actual encryption state. If a customer-managed key is required, prepare an appropriate symmetric KMS key in the same Region and its permissions, then specify Provider.KeyArn and Resources: [secrets] in EncryptionConfig. On Kubernetes 1.28 and later, envelope encryption covers all API data regardless of this resource list. For an existing cluster, review the supported update procedure and change set, and control key disabling and deletion.
Examples
Supply a currently supported Kubernetes version, a cluster role, security groups and subnets in different Availability Zones. The first example also uses default envelope encryption on Kubernetes 1.28 and later. The second specifies a customer-managed key required by an organization.
Using an AWS-owned key
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
KubernetesVersion:
Type: String
ClusterRoleArn:
Type: String
ClusterSecurityGroups:
Type: List<AWS::EC2::SecurityGroup::Id>
ClusterSubnets:
Type: List<AWS::EC2::Subnet::Id>
Resources:
MyEKSClusterA:
Type: AWS::EKS::Cluster
Properties:
Name: dev
Version: !Ref KubernetesVersion
RoleArn: !Ref ClusterRoleArn
ResourcesVpcConfig:
SecurityGroupIds: !Ref ClusterSecurityGroups
SubnetIds: !Ref ClusterSubnets
Specifying a customer-managed key
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
EncryptionKeyArn:
Type: String
KubernetesVersion:
Type: String
ClusterRoleArn:
Type: String
ClusterSecurityGroups:
Type: List<AWS::EC2::SecurityGroup::Id>
ClusterSubnets:
Type: List<AWS::EC2::Subnet::Id>
Resources:
MyEKSClusterA:
Type: AWS::EKS::Cluster
Properties:
Name: dev
Version: !Ref KubernetesVersion
RoleArn: !Ref ClusterRoleArn
ResourcesVpcConfig:
SecurityGroupIds: !Ref ClusterSecurityGroups
SubnetIds: !Ref ClusterSubnets
EncryptionConfig:
- Provider:
KeyArn: !Ref EncryptionKeyArn
Resources:
- secrets