Review the Secrets Manager encryption key

Distinguish Secrets Manager default encryption from custom key-policy and cross-account requirements.

Description

When KmsKeyId is omitted, Secrets Manager encrypts secret values with the AWS managed aws/secretsmanager key. Omission does not disable encryption. A customer managed key is needed for direct control over key policy and lifecycle or for access to the secret from another account.

Potential impact

The default key may not meet separate key-management or cross-account access requirements. Incorrect key permissions can prevent required secret retrieval.

Remediation

When needed, set KmsKeyId to an actual customer managed key ARN. Review both the secret access policy and KMS key policy, allowing only required principals and actions, then verify that the application can still retrieve the secret.

Examples

These excerpts compare encryption-key choices. Neither generates or supplies a secret value, so they create empty secrets. Manage actual values through a separate suitable generation and storage process.

Before

yaml
Resources:
  MySecret:
    Type: AWS::SecretsManager::Secret
    Properties:
      Description: secret description

The default aws/secretsmanager key will be used when a value is stored.

After

yaml
Resources:
  MySecret:
    Type: AWS::SecretsManager::Secret
    Properties:
      Description: secret description
      KmsKeyId: !Ref SecretKeyArn

The customer managed key supplied through SecretKeyArn is used. Specifying a key alone does not remove excessive access to the secret.

References