EKS encryption key configuration needs review

Distinguish EKS default encryption from requirements for a customer-managed KMS key.

Description

EKS encrypts the disks storing etcd data for every cluster. Kubernetes 1.28 and later also use default envelope encryption for all Kubernetes API data with an AWS-owned key. Absence of EncryptionConfig therefore does not establish that cluster data is stored in plaintext.

Configure a customer-managed KMS key when you must control its policy and lifecycle. This setting is separate from encryption of data on nodes or EBS volumes.

Potential impact

A default key may not satisfy an organization’s key-control requirements where a customer-managed key is required. Conversely, deleting an active key or removing required permissions can interrupt cluster operation and data access. Encryption does not replace Kubernetes access controls.

Remediation

Check the cluster version and actual encryption state. If a customer-managed key is required, prepare an appropriate symmetric KMS key in the same Region and its permissions, then specify Provider.KeyArn and Resources: [secrets] in EncryptionConfig. On Kubernetes 1.28 and later, envelope encryption covers all API data regardless of this resource list. For an existing cluster, review the supported update procedure and change set, and control key disabling and deletion.

Examples

Supply a currently supported Kubernetes version, a cluster role, security groups and subnets in different Availability Zones. The first example also uses default envelope encryption on Kubernetes 1.28 and later. The second specifies a customer-managed key required by an organization.

Using an AWS-owned key

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  KubernetesVersion:
    Type: String
  ClusterRoleArn:
    Type: String
  ClusterSecurityGroups:
    Type: List<AWS::EC2::SecurityGroup::Id>
  ClusterSubnets:
    Type: List<AWS::EC2::Subnet::Id>
Resources:
  MyEKSClusterA:
    Type: AWS::EKS::Cluster
    Properties:
      Name: dev
      Version: !Ref KubernetesVersion
      RoleArn: !Ref ClusterRoleArn
      ResourcesVpcConfig:
        SecurityGroupIds: !Ref ClusterSecurityGroups
        SubnetIds: !Ref ClusterSubnets

Specifying a customer-managed key

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  EncryptionKeyArn:
    Type: String
  KubernetesVersion:
    Type: String
  ClusterRoleArn:
    Type: String
  ClusterSecurityGroups:
    Type: List<AWS::EC2::SecurityGroup::Id>
  ClusterSubnets:
    Type: List<AWS::EC2::Subnet::Id>
Resources:
  MyEKSClusterA:
    Type: AWS::EKS::Cluster
    Properties:
      Name: dev
      Version: !Ref KubernetesVersion
      RoleArn: !Ref ClusterRoleArn
      ResourcesVpcConfig:
        SecurityGroupIds: !Ref ClusterSecurityGroups
        SubnetIds: !Ref ClusterSubnets
      EncryptionConfig:
        - Provider:
            KeyArn: !Ref EncryptionKeyArn
          Resources:
            - secrets

References