Description
EFS provides shared storage for multiple instances and containers. Encryption at rest protects files and metadata; an unencrypted file system lacks this protection.
Explicitly request encryption when creating a Crossplane FileSystem and maintain the same requirement in Compositions and templates. Encryption does not restrict users who can legitimately mount the file system and read its files.
Potential impact
Unauthorized acquisition of stored data can expose shared documents, uploads or application data. It may also leave organizational encryption requirements unmet.
Remediation
- Set
spec.forProvider.encryptedtotruefor new file systems and verify the required key and permissions. - An existing file system’s encryption setting cannot be changed. Preserve the source and backups, migrate data to a new encrypted file system, and then switch mounts and applications.
- Restrict file permissions, mount targets and network access, and configure encryption in transit separately.
Examples
These compare creation settings for new file systems. Prepare the example ProviderConfig, required mount targets and networking separately. The resource names differ, and the examples do not migrate data automatically.
Before
apiVersion: efs.aws.crossplane.io/v1alpha1
kind: FileSystem
metadata:
name: example3
spec:
forProvider:
region: us-east-1
encrypted: false
providerConfigRef:
name: example
This creates a file system without encryption at rest.
After
apiVersion: efs.aws.crossplane.io/v1alpha1
kind: FileSystem
metadata:
name: example
spec:
forProvider:
region: us-east-1
encrypted: true
providerConfigRef:
name: example
This requests encryption for a new file system. Migrate existing data and verify actual encryption and file access.