Description
Explicitly configure storage encryption for a new database created through Crossplane’s RDSInstance. An unencrypted database lacks encryption protection for storage and associated logs, backups and snapshots.
Including the setting in templates and Compositions helps apply the requirement consistently across environments. Encryption does not prevent reads by users with legitimate database permissions, so access controls are also necessary.
Potential impact
Unauthorized acquisition of stored data or backups can expose sensitive business information. It may also leave organizational encryption requirements unmet.
Remediation
- Explicitly set
spec.forProvider.storageEncrypted: truefor new instances and prepare the required KMS key and permissions. - Changing a flag does not encrypt an existing unencrypted instance. Use a supported migration, such as creating an encrypted snapshot copy and restoring a new instance.
- Preserve backups and the source, and verify data consistency, connection cutover and actual encryption. Review authentication, public access and TLS separately.
Examples
These are new-instance creation excerpts. Prepare credentials, networking and ProviderConfig in the complete configuration. The examples use different resource names for comparison and do not migrate an existing database’s data.
Before
apiVersion: database.aws.crossplane.io/v1beta1
kind: RDSInstance
metadata:
name: rds3
spec:
forProvider:
allocatedStorage: 50
dbInstanceClass: db.t3.medium
engine: mysql
region: us-west-2
publiclyAccessible: false
storageEncrypted: false
storageType: gp2
This does not request storage encryption for the new MySQL instance.
After
apiVersion: database.aws.crossplane.io/v1beta1
kind: RDSInstance
metadata:
name: rds1
spec:
forProvider:
allocatedStorage: 50
dbInstanceClass: db.t3.medium
engine: mysql
region: us-west-2
publiclyAccessible: false
storageEncrypted: true
storageType: gp2
This requests storage encryption with storageEncrypted: true. Verify the actual state and data access after creation.