SageMaker notebook encryption key settings need review

Distinguish SageMaker notebook default encryption from requirements for a customer managed key.

Description

SageMaker notebook instances can hold sensitive training data, preprocessing results and experiment outputs. Without a specified KMS key, SageMaker encrypts both the operating-system and ML data volumes with a system-managed key. An omitted KmsKeyId does not mean unencrypted storage.

Organizations that require separate key policies or lifecycle control should select a customer managed KMS key for the ML data volume. This setting does not replace notebook access controls or encryption of output stored in S3.

Potential impact

The default key may not meet organizational key-management requirements. Removing required key permissions or disabling a key can interrupt data access and notebook operation.

Remediation

  • Choose default encryption or a customer managed key according to requirements. If a separate key is needed, specify a real, enabled key ARN in KmsKeyId and grant the necessary permissions.
  • Store files that require this key’s protection in the ML data volume at /home/ec2-user/SageMaker. Check S3 encryption and access permissions separately.
  • Changing KmsKeyId in CloudFormation replaces the instance. Back up required files, migrate them to the new instance and verify operation.

Examples

These are notebook-creation excerpts. Define ExecutionRole with the required permissions and the key parameter in the full template.

Default encryption key

yaml
Resources:
  BasicNotebookInstance:
    Type: AWS::SageMaker::NotebookInstance
    Properties:
      InstanceType: ml.t2.large
      RoleArn: !GetAtt ExecutionRole.Arn

This uses system-managed encryption. Review whether separate key control is required.

Customer managed key

yaml
Resources:
  BasicNotebookInstance:
    Type: AWS::SageMaker::NotebookInstance
    Properties:
      InstanceType: ml.t2.large
      RoleArn: !GetAtt ExecutionRole.Arn
      KmsKeyId: !Ref NotebookKmsKeyArn

This selects the key for the ML data volume. Access by users authorized to use the notebook still requires separate controls.

References