RDS instance without configured storage encryption

Encrypt RDS storage created through Crossplane and migrate existing data through supported procedures.

Description

Explicitly configure storage encryption for a new database created through Crossplane’s RDSInstance. An unencrypted database lacks encryption protection for storage and associated logs, backups and snapshots.

Including the setting in templates and Compositions helps apply the requirement consistently across environments. Encryption does not prevent reads by users with legitimate database permissions, so access controls are also necessary.

Potential impact

Unauthorized acquisition of stored data or backups can expose sensitive business information. It may also leave organizational encryption requirements unmet.

Remediation

  • Explicitly set spec.forProvider.storageEncrypted: true for new instances and prepare the required KMS key and permissions.
  • Changing a flag does not encrypt an existing unencrypted instance. Use a supported migration, such as creating an encrypted snapshot copy and restoring a new instance.
  • Preserve backups and the source, and verify data consistency, connection cutover and actual encryption. Review authentication, public access and TLS separately.

Examples

These are new-instance creation excerpts. Prepare credentials, networking and ProviderConfig in the complete configuration. The examples use different resource names for comparison and do not migrate an existing database’s data.

Before

yaml
apiVersion: database.aws.crossplane.io/v1beta1
kind: RDSInstance
metadata:
  name: rds3
spec:
  forProvider:
    allocatedStorage: 50
    dbInstanceClass: db.t3.medium
    engine: mysql
    region: us-west-2
    publiclyAccessible: false
    storageEncrypted: false
    storageType: gp2

This does not request storage encryption for the new MySQL instance.

After

yaml
apiVersion: database.aws.crossplane.io/v1beta1
kind: RDSInstance
metadata:
  name: rds1
spec:
  forProvider:
    allocatedStorage: 50
    dbInstanceClass: db.t3.medium
    engine: mysql
    region: us-west-2
    publiclyAccessible: false
    storageEncrypted: true
    storageType: gp2

This requests storage encryption with storageEncrypted: true. Verify the actual state and data access after creation.

References