Elasticsearch domain with encryption at rest disabled

Encrypt stored Elasticsearch indexes and related data, and protect separate copies as well.

Description

Elasticsearch domain encryption at rest uses a KMS key to protect indexes, application data and automated snapshots, among other stored data. This protection matters when search data includes operational logs or customer information. Encryption does not prevent authorized access through search APIs, so authentication and access policies remain necessary.

Potential impact

Without encryption at rest, unauthorized acquisition of stored data increases the risk of exposure. Organizational requirements for protecting stored data may also remain unmet.

Remediation

Specify EncryptionAtRestOptions.Enabled: true and an appropriate KmsKeyId with a supported engine version and instance type. Enabling encryption on an existing Elasticsearch domain requires version 6.7 or later and compliance with the service’s update conditions. Review the change and recovery plans, then verify the actual encryption state.

Encryption at rest cannot be disabled once enabled, and disabling or deleting an active key can interrupt data access. Preserve required key permissions and protect manual snapshot repositories and exported logs separately.

Examples

Supply an Elasticsearch version supporting encryption and the instance type. The revised template also requires an actual approved KMS key ID or ARN. Access policies and networking require separate configuration; these settings alone do not provide a complete secure domain configuration.

Before

yaml
Parameters:
  ElasticsearchVersion:
    Type: String
Resources:
  ElasticsearchDomain:
    Type: AWS::Elasticsearch::Domain
    Properties:
      DomainName: test
      ElasticsearchVersion: !Ref ElasticsearchVersion
      ElasticsearchClusterConfig:
        InstanceType: t3.small.elasticsearch
      EncryptionAtRestOptions:
        Enabled: false
      EBSOptions:
        EBSEnabled: true
        VolumeSize: 20
        VolumeType: gp2

After

yaml
Parameters:
  ElasticsearchVersion:
    Type: String
  EncryptionKeyId:
    Type: String
Resources:
  ElasticsearchDomain:
    Type: AWS::Elasticsearch::Domain
    Properties:
      DomainName: test
      ElasticsearchVersion: !Ref ElasticsearchVersion
      ElasticsearchClusterConfig:
        InstanceType: t3.small.elasticsearch
      EncryptionAtRestOptions:
        Enabled: true
        KmsKeyId: !Ref EncryptionKeyId
      EBSOptions:
        EBSEnabled: true
        VolumeSize: 20
        VolumeType: gp2

References