RDS instance storage encryption settings need review

Verify actual RDS instance encryption and settings inherited from a source database or snapshot.

Description

RDS encryption at rest protects database storage and associated logs, backups and snapshots. An actually unencrypted instance lacks this protection.

Specify required encryption for a new ordinary RDS instance. Read replicas and snapshot restores inherit encryption settings from their source, while Aurora instance encryption is managed by the cluster. An omitted StorageEncrypted property in an instance template therefore does not establish that storage is unencrypted.

Potential impact

Unauthorized acquisition of unencrypted data or backups can expose sensitive information. Database permissions and TLS remain necessary with storage encryption, and an unavailable KMS key can interrupt the service.

Remediation

  • Set StorageEncrypted: true and the required key and permissions for new ordinary instances. Verify actual instance and backup encryption.
  • Migrate an existing unencrypted instance through a supported procedure, such as taking a snapshot, creating an encrypted copy and restoring a new instance. Verify backups, data consistency and connection cutover.
  • An unencrypted source cannot have an encrypted read replica. An encrypted cross-Region replica also requires a KMS key in the destination Region.

Examples

These are excerpts for cross-Region read replicas. Define the referenced parameters in the full template and supply actual source ARNs and Regions, a supported instance class and the destination Region’s key. Configure networking separately. The examples compare different source states; they do not encrypt an existing database.

Replica of an unencrypted source

yaml
Resources:
  MyDBSmall:
    Type: AWS::RDS::DBInstance
    Properties:
      DBInstanceClass: !Ref DBInstanceType
      SourceDBInstanceIdentifier: !Ref UnencryptedSourceDBArn
      SourceRegion: !Ref SourceRegion

This inherits the unencrypted source’s setting. Adding encryption options to the replica cannot convert the source’s unencrypted data.

Replica of an encrypted source

yaml
Resources:
  MyDBSmall:
    Type: AWS::RDS::DBInstance
    Properties:
      DBInstanceClass: !Ref DBInstanceType
      SourceDBInstanceIdentifier: !Ref EncryptedSourceDBArn
      SourceRegion: !Ref SourceRegion
      KmsKeyId: !Ref MyKey

This uses an already encrypted source and a KMS key in the destination Region. Do not specify StorageEncrypted separately for the read replica because it inherits that setting. Do not apply a source-changing update without a cutover plan.

References