Description
Lambda encrypts environment variables at rest by default. A missing KmsKeyArn on a SAM function does not mean those variables are unencrypted. Use a customer managed key when direct control of key policy and lifecycle is required.
Potential impact
The configuration may not meet the organization’s requirements for separate key management or access control.
Remediation
If a customer managed key is required, set KmsKeyArn to its ARN and configure the necessary key permissions. Keep actual secrets out of templates and manage them through services such as Secrets Manager.
Examples
The examples only compare key selection. example-token is not a real secret, and the KMS setting does not encrypt values in source files. The image URI is omitted.
Before
Resources:
Function:
Type: AWS::Serverless::Function
Properties:
PackageType: Image
Environment:
Variables:
API_TOKEN: example-token
After
Resources:
Function:
Type: AWS::Serverless::Function
Properties:
PackageType: Image
Environment:
Variables:
API_TOKEN: example-token
KmsKeyArn: arn:aws:kms:ap-northeast-2:123456789012:key/12345678-1234-1234-1234-123456789012