Description
Encryption at rest protects database storage and associated backups and snapshots. An actually unencrypted cluster lacks this protection, but template values alone do not establish the current storage state.
Aurora encrypts new clusters created from February 18, 2026 onward with an AWS-owned key by default. Snapshots, clones and read replicas of older unencrypted sources can remain unencrypted. Distinguish Aurora from other RDS cluster types, and creation from restoration, when checking actual encryption and key requirements.
Potential impact
Unauthorized acquisition of actually unencrypted storage or backups can expose business data. Encryption does not block legitimate database users from reading data, and loss of access to an encryption key can interrupt the service.
Remediation
- Specify the required storage encryption and key for new configurations. When a customer managed key is required, prepare
StorageEncrypted: true, an appropriateKmsKeyIdand the required permissions. - Migrate existing unencrypted Aurora clusters into new encrypted clusters through supported procedures such as snapshot restoration. A setting change does not automatically migrate data.
- Preserve backups and review the change set, data consistency and connection cutover. Verify actual encryption, keys and data access afterward, and maintain authentication and TLS separately.
Examples
These compare requested settings for a new Aurora PostgreSQL cluster. Configure DB instances and networking separately. Both use a managed master password; neither is a migration procedure for an existing cluster.
No explicit encryption request
Parameters:
DBUsername:
Type: String
Resources:
RDSCluster:
Type: AWS::RDS::DBCluster
DeletionPolicy: Snapshot
UpdateReplacePolicy: Snapshot
Properties:
Engine: aurora-postgresql
MasterUsername: !Ref DBUsername
ManageMasterUserPassword: true
StorageEncrypted: false
With current Aurora defaults for new clusters, this value alone does not mean plaintext storage. Check the actual state of existing data.
Explicit encryption and key
Parameters:
DBUsername:
Type: String
DatabaseKmsKeyArn:
Type: String
Resources:
RDSCluster:
Type: AWS::RDS::DBCluster
DeletionPolicy: Snapshot
UpdateReplacePolicy: Snapshot
Properties:
Engine: aurora-postgresql
MasterUsername: !Ref DBUsername
ManageMasterUserPassword: true
StorageEncrypted: true
KmsKeyId: !Ref DatabaseKmsKeyArn
Provide a real KMS key ARN usable in the same Region and the required permissions. Retaining snapshots does not replace data restoration or application cutover.