Redshift storage encryption settings need review

Verify actual Redshift encryption and keys, and protect existing unencrypted clusters.

Description

Redshift is a data warehouse that can store large volumes of business data, logs and aggregated information. Encryption at rest protects these data and snapshots.

The current Redshift API encrypts new clusters by default and rejects an explicit Encrypted: false request. An omitted template option does not establish unencrypted storage. Check actual encryption and keys, including on older clusters.

Potential impact

Unauthorized acquisition of actually unencrypted storage or snapshots can expose analytical data and sensitive information. Database permissions and network restrictions remain necessary even with encryption enabled.

Remediation

  • Explicitly request Encrypted: true for new clusters and choose a KMS key that meets organizational requirements.
  • Use a supported encryption conversion for existing unencrypted clusters. Preserve backups and plan for read-only operation and other operational effects during conversion.
  • Verify actual encryption and normal data access afterward, and retain required key permissions.

Examples

These are creation excerpts. Define the referenced values in the full template, supply a securely managed password, and choose a node type supported for single-node deployment in the Region. Review the retained public-access setting and networking separately.

Encryption option omitted

yaml
Resources:
  RedshiftCluster:
    Type: AWS::Redshift::Cluster
    Properties:
      DBName: !Sub ${DatabaseName}
      MasterUserPassword: !Ref MasterUserPassword
      MasterUsername: !Ref MasterUsername
      PubliclyAccessible: true
      ClusterType: single-node
      NodeType: !Ref RedshiftNodeType
      Port: 5439

Current creation defaults provide encryption. This omission alone does not mean plaintext storage.

Explicit encryption requirement

yaml
Resources:
  RedshiftCluster:
    Type: AWS::Redshift::Cluster
    Properties:
      DBName: !Sub ${DatabaseName}
      MasterUserPassword: !Ref MasterUserPassword
      MasterUsername: !Ref MasterUsername
      PubliclyAccessible: true
      ClusterType: single-node
      NodeType: !Ref RedshiftNodeType
      Port: 5439
      Encrypted: true

This states the encryption requirement. Before modifying an existing cluster, verify its actual state and the supported conversion procedure.

References