Description
RDS encryption at rest protects database storage and associated logs, backups and snapshots. An actually unencrypted instance lacks this protection.
Specify required encryption for a new ordinary RDS instance. Read replicas and snapshot restores inherit encryption settings from their source, while Aurora instance encryption is managed by the cluster. An omitted StorageEncrypted property in an instance template therefore does not establish that storage is unencrypted.
Potential impact
Unauthorized acquisition of unencrypted data or backups can expose sensitive information. Database permissions and TLS remain necessary with storage encryption, and an unavailable KMS key can interrupt the service.
Remediation
- Set
StorageEncrypted: trueand the required key and permissions for new ordinary instances. Verify actual instance and backup encryption. - Migrate an existing unencrypted instance through a supported procedure, such as taking a snapshot, creating an encrypted copy and restoring a new instance. Verify backups, data consistency and connection cutover.
- An unencrypted source cannot have an encrypted read replica. An encrypted cross-Region replica also requires a KMS key in the destination Region.
Examples
These are excerpts for cross-Region read replicas. Define the referenced parameters in the full template and supply actual source ARNs and Regions, a supported instance class and the destination Region’s key. Configure networking separately. The examples compare different source states; they do not encrypt an existing database.
Replica of an unencrypted source
Resources:
MyDBSmall:
Type: AWS::RDS::DBInstance
Properties:
DBInstanceClass: !Ref DBInstanceType
SourceDBInstanceIdentifier: !Ref UnencryptedSourceDBArn
SourceRegion: !Ref SourceRegion
This inherits the unencrypted source’s setting. Adding encryption options to the replica cannot convert the source’s unencrypted data.
Replica of an encrypted source
Resources:
MyDBSmall:
Type: AWS::RDS::DBInstance
Properties:
DBInstanceClass: !Ref DBInstanceType
SourceDBInstanceIdentifier: !Ref EncryptedSourceDBArn
SourceRegion: !Ref SourceRegion
KmsKeyId: !Ref MyKey
This uses an already encrypted source and a KMS key in the destination Region. Do not specify StorageEncrypted separately for the read replica because it inherits that setting. Do not apply a source-changing update without a cutover plan.