ElastiCache Redis replication group with encryption at rest disabled

Encrypt ElastiCache Redis OSS disk data and backups, and plan migration of existing groups.

Description

ElastiCache Redis OSS encryption at rest protects data written to disk during synchronization, backup and swap operations, as well as backups. If a cache holds sessions, tokens or personal information, its stored copies also need protection. Encryption at rest does not replace encrypted client connections or user authentication.

Potential impact

Unauthorized acquisition of unencrypted stored data or backups increases the risk of sensitive information exposure. It can also leave organizational data-protection requirements for the cache unmet.

Remediation

Specify AtRestEncryptionEnabled: true for new replication groups and review the required KMS key and permissions. This option defaults to false for Redis OSS, so verify the actual state.

The setting cannot be toggled on an existing group. Restore or migrate data into a new encrypted group, verify application connectivity and data consistency, then switch clients over. Prepare backup and recovery plans before the cutover, and configure encryption in transit and authentication separately.

Examples

Supply a cache subnet group in the actual VPC and security groups allowing only required access. These examples compare single-node creation settings; they do not configure high availability or migrate existing data.

Before

yaml
Parameters:
  CacheSubnetGroupName:
    Type: String
  CacheSecurityGroups:
    Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
  ReplicationGroup:
    Type: AWS::ElastiCache::ReplicationGroup
    Properties:
      ReplicationGroupDescription: example
      AtRestEncryptionEnabled: false
      Engine: redis
      CacheNodeType: cache.t3.micro
      NumCacheClusters: 1
      CacheSubnetGroupName: !Ref CacheSubnetGroupName
      SecurityGroupIds: !Ref CacheSecurityGroups

After

yaml
Parameters:
  CacheSubnetGroupName:
    Type: String
  CacheSecurityGroups:
    Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
  ReplicationGroup:
    Type: AWS::ElastiCache::ReplicationGroup
    Properties:
      ReplicationGroupDescription: example
      AtRestEncryptionEnabled: true
      Engine: redis
      CacheNodeType: cache.t3.micro
      NumCacheClusters: 1
      CacheSubnetGroupName: !Ref CacheSubnetGroupName
      SecurityGroupIds: !Ref CacheSecurityGroups

References