Elasticsearch encryption key configuration needs review

Check the actual encryption state and KMS key selection for an Elasticsearch domain.

Description

Review both encryption at rest and KMS key selection for an Elasticsearch domain. Absence of KmsKeyId in a template does not by itself establish plaintext storage. The CloudFormation property definition for AWS::Elasticsearch::Domain requires a key when enabling encryption.

Choose a customer-managed key when organizational requirements call for direct control of key policy and lifecycle. An encrypted domain does not become public merely because it lacks a customer-managed key.

Potential impact

Unsuitable key selection or permissions can leave audit and separation-of-duty requirements unmet. Disabling or deleting an active key can make domain data inaccessible.

Remediation

Check the actual domain encryption state and key, then specify an appropriate symmetric KMS key in EncryptionAtRestOptions.KmsKeyId. Grant required service access while restricting key administration. Replacing the key of an encrypted domain with a different key is unsupported, so plan migration to a new domain if needed. Verify protection against key deletion and data recovery.

Examples

The first template is incomplete because it omits the key; it is not evidence of plaintext storage. The second accepts an actual approved key ID or ARN. Specify an Elasticsearch version supporting the instance type and encryption, and configure access policies and network controls separately.

Key omitted

yaml
Parameters:
  ElasticsearchVersion:
    Type: String
Resources:
  ElasticsearchDomain:
    Type: AWS::Elasticsearch::Domain
    Properties:
      DomainName: test
      ElasticsearchVersion: !Ref ElasticsearchVersion
      ElasticsearchClusterConfig:
        InstanceType: t3.small.elasticsearch
      EncryptionAtRestOptions:
        Enabled: true
      EBSOptions:
        EBSEnabled: true
        VolumeSize: 20
        VolumeType: gp2

Key specified

yaml
Parameters:
  ElasticsearchVersion:
    Type: String
  EncryptionKeyId:
    Type: String
Resources:
  ElasticsearchDomain:
    Type: AWS::Elasticsearch::Domain
    Properties:
      DomainName: test
      ElasticsearchVersion: !Ref ElasticsearchVersion
      ElasticsearchClusterConfig:
        InstanceType: t3.small.elasticsearch
      EncryptionAtRestOptions:
        Enabled: true
        KmsKeyId: !Ref EncryptionKeyId
      EBSOptions:
        EBSEnabled: true
        VolumeSize: 20
        VolumeType: gp2

References