Description
Elasticsearch domain encryption at rest uses a KMS key to protect indexes, application data and automated snapshots, among other stored data. This protection matters when search data includes operational logs or customer information. Encryption does not prevent authorized access through search APIs, so authentication and access policies remain necessary.
Potential impact
Without encryption at rest, unauthorized acquisition of stored data increases the risk of exposure. Organizational requirements for protecting stored data may also remain unmet.
Remediation
Specify EncryptionAtRestOptions.Enabled: true and an appropriate KmsKeyId with a supported engine version and instance type. Enabling encryption on an existing Elasticsearch domain requires version 6.7 or later and compliance with the service’s update conditions. Review the change and recovery plans, then verify the actual encryption state.
Encryption at rest cannot be disabled once enabled, and disabling or deleting an active key can interrupt data access. Preserve required key permissions and protect manual snapshot repositories and exported logs separately.
Examples
Supply an Elasticsearch version supporting encryption and the instance type. The revised template also requires an actual approved KMS key ID or ARN. Access policies and networking require separate configuration; these settings alone do not provide a complete secure domain configuration.
Before
Parameters:
ElasticsearchVersion:
Type: String
Resources:
ElasticsearchDomain:
Type: AWS::Elasticsearch::Domain
Properties:
DomainName: test
ElasticsearchVersion: !Ref ElasticsearchVersion
ElasticsearchClusterConfig:
InstanceType: t3.small.elasticsearch
EncryptionAtRestOptions:
Enabled: false
EBSOptions:
EBSEnabled: true
VolumeSize: 20
VolumeType: gp2
After
Parameters:
ElasticsearchVersion:
Type: String
EncryptionKeyId:
Type: String
Resources:
ElasticsearchDomain:
Type: AWS::Elasticsearch::Domain
Properties:
DomainName: test
ElasticsearchVersion: !Ref ElasticsearchVersion
ElasticsearchClusterConfig:
InstanceType: t3.small.elasticsearch
EncryptionAtRestOptions:
Enabled: true
KmsKeyId: !Ref EncryptionKeyId
EBSOptions:
EBSEnabled: true
VolumeSize: 20
VolumeType: gp2