Customer managed key not specified for SAM function environment variables

Specify a customer managed KMS key when a SAM function requires separate key control.

Description

Lambda encrypts environment variables at rest by default. A missing KmsKeyArn on a SAM function does not mean those variables are unencrypted. Use a customer managed key when direct control of key policy and lifecycle is required.

Potential impact

The configuration may not meet the organization’s requirements for separate key management or access control.

Remediation

If a customer managed key is required, set KmsKeyArn to its ARN and configure the necessary key permissions. Keep actual secrets out of templates and manage them through services such as Secrets Manager.

Examples

The examples only compare key selection. example-token is not a real secret, and the KMS setting does not encrypt values in source files. The image URI is omitted.

Before

yaml
Resources:
  Function:
    Type: AWS::Serverless::Function
    Properties:
      PackageType: Image
      Environment:
        Variables:
          API_TOKEN: example-token

After

yaml
Resources:
  Function:
    Type: AWS::Serverless::Function
    Properties:
      PackageType: Image
      Environment:
        Variables:
          API_TOKEN: example-token
      KmsKeyArn: arn:aws:kms:ap-northeast-2:123456789012:key/12345678-1234-1234-1234-123456789012

References