Description
When KmsKeyId is omitted, Secrets Manager encrypts secret values with the AWS managed aws/secretsmanager key. Omission does not disable encryption. A customer managed key is needed for direct control over key policy and lifecycle or for access to the secret from another account.
Potential impact
The default key may not meet separate key-management or cross-account access requirements. Incorrect key permissions can prevent required secret retrieval.
Remediation
When needed, set KmsKeyId to an actual customer managed key ARN. Review both the secret access policy and KMS key policy, allowing only required principals and actions, then verify that the application can still retrieve the secret.
Examples
These excerpts compare encryption-key choices. Neither generates or supplies a secret value, so they create empty secrets. Manage actual values through a separate suitable generation and storage process.
Before
Resources:
MySecret:
Type: AWS::SecretsManager::Secret
Properties:
Description: secret description
The default aws/secretsmanager key will be used when a value is stored.
After
Resources:
MySecret:
Type: AWS::SecretsManager::Secret
Properties:
Description: secret description
KmsKeyId: !Ref SecretKeyArn
The customer managed key supplied through SecretKeyArn is used. Specifying a key alone does not remove excessive access to the secret.