RDS cluster storage encryption settings need review

Verify RDS cluster storage encryption and keys, and migrate existing unencrypted data through supported procedures.

Description

Encryption at rest protects database storage and associated backups and snapshots. An actually unencrypted cluster lacks this protection, but template values alone do not establish the current storage state.

Aurora encrypts new clusters created from February 18, 2026 onward with an AWS-owned key by default. Snapshots, clones and read replicas of older unencrypted sources can remain unencrypted. Distinguish Aurora from other RDS cluster types, and creation from restoration, when checking actual encryption and key requirements.

Potential impact

Unauthorized acquisition of actually unencrypted storage or backups can expose business data. Encryption does not block legitimate database users from reading data, and loss of access to an encryption key can interrupt the service.

Remediation

  • Specify the required storage encryption and key for new configurations. When a customer managed key is required, prepare StorageEncrypted: true, an appropriate KmsKeyId and the required permissions.
  • Migrate existing unencrypted Aurora clusters into new encrypted clusters through supported procedures such as snapshot restoration. A setting change does not automatically migrate data.
  • Preserve backups and review the change set, data consistency and connection cutover. Verify actual encryption, keys and data access afterward, and maintain authentication and TLS separately.

Examples

These compare requested settings for a new Aurora PostgreSQL cluster. Configure DB instances and networking separately. Both use a managed master password; neither is a migration procedure for an existing cluster.

No explicit encryption request

yaml
Parameters:
  DBUsername:
    Type: String
Resources:
  RDSCluster:
    Type: AWS::RDS::DBCluster
    DeletionPolicy: Snapshot
    UpdateReplacePolicy: Snapshot
    Properties:
      Engine: aurora-postgresql
      MasterUsername: !Ref DBUsername
      ManageMasterUserPassword: true
      StorageEncrypted: false

With current Aurora defaults for new clusters, this value alone does not mean plaintext storage. Check the actual state of existing data.

Explicit encryption and key

yaml
Parameters:
  DBUsername:
    Type: String
  DatabaseKmsKeyArn:
    Type: String
Resources:
  RDSCluster:
    Type: AWS::RDS::DBCluster
    DeletionPolicy: Snapshot
    UpdateReplacePolicy: Snapshot
    Properties:
      Engine: aurora-postgresql
      MasterUsername: !Ref DBUsername
      ManageMasterUserPassword: true
      StorageEncrypted: true
      KmsKeyId: !Ref DatabaseKmsKeyArn

Provide a real KMS key ARN usable in the same Region and the required permissions. Retaining snapshots does not replace data restoration or application cutover.

References