Description
Review both encryption at rest and KMS key selection for an Elasticsearch domain. Absence of KmsKeyId in a template does not by itself establish plaintext storage. The CloudFormation property definition for AWS::Elasticsearch::Domain requires a key when enabling encryption.
Choose a customer-managed key when organizational requirements call for direct control of key policy and lifecycle. An encrypted domain does not become public merely because it lacks a customer-managed key.
Potential impact
Unsuitable key selection or permissions can leave audit and separation-of-duty requirements unmet. Disabling or deleting an active key can make domain data inaccessible.
Remediation
Check the actual domain encryption state and key, then specify an appropriate symmetric KMS key in EncryptionAtRestOptions.KmsKeyId. Grant required service access while restricting key administration. Replacing the key of an encrypted domain with a different key is unsupported, so plan migration to a new domain if needed. Verify protection against key deletion and data recovery.
Examples
The first template is incomplete because it omits the key; it is not evidence of plaintext storage. The second accepts an actual approved key ID or ARN. Specify an Elasticsearch version supporting the instance type and encryption, and configure access policies and network controls separately.
Key omitted
Parameters:
ElasticsearchVersion:
Type: String
Resources:
ElasticsearchDomain:
Type: AWS::Elasticsearch::Domain
Properties:
DomainName: test
ElasticsearchVersion: !Ref ElasticsearchVersion
ElasticsearchClusterConfig:
InstanceType: t3.small.elasticsearch
EncryptionAtRestOptions:
Enabled: true
EBSOptions:
EBSEnabled: true
VolumeSize: 20
VolumeType: gp2
Key specified
Parameters:
ElasticsearchVersion:
Type: String
EncryptionKeyId:
Type: String
Resources:
ElasticsearchDomain:
Type: AWS::Elasticsearch::Domain
Properties:
DomainName: test
ElasticsearchVersion: !Ref ElasticsearchVersion
ElasticsearchClusterConfig:
InstanceType: t3.small.elasticsearch
EncryptionAtRestOptions:
Enabled: true
KmsKeyId: !Ref EncryptionKeyId
EBSOptions:
EBSEnabled: true
VolumeSize: 20
VolumeType: gp2