Review the EFS customer managed KMS key

Review EFS encryption separately from requirements for a customer managed KMS key.

Description

A customer managed KMS key lets your organization control the key policy and lifecycle for EFS. An encrypted file system can use an AWS managed key when no customer key is specified, so an omitted key setting does not establish that storage is unencrypted.

Encryption at rest does not replace file permissions or TLS for mount connections.

Potential impact

  • The default key may not meet organizational controls that require a customer managed key.
  • An actually unencrypted file system lacks protection from encryption at rest. Disabling or deleting a key in use can instead interrupt file access.

Remediation

Set encrypted: true for a new file system and, where a customer key is required, specify an available key in the same Region through kmsKeyID. Check the key policy and necessary permissions. An existing file system’s encryption state and KMS key cannot be changed; plan and verify data migration and mount cutover to a new file system.

Examples

Use a key ID and provider configuration appropriate for your environment.

Before

yaml
apiVersion: efs.aws.crossplane.io/v1alpha1
kind: FileSystem
metadata:
  name: example
spec:
  forProvider:
    region: us-east-1
    encrypted: false
  providerConfigRef:
    name: example

This does not request encryption at rest for the new file system.

After

yaml
apiVersion: efs.aws.crossplane.io/v1alpha1
kind: FileSystem
metadata:
  name: example
spec:
  forProvider:
    region: us-east-1
    kmsKeyID: 1234abcd-12ab-34cd-56ef-1234567890ab
    encrypted: true
  providerConfigRef:
    name: example

This requests a new file system encrypted with the specified KMS key. It does not automatically migrate data from an existing resource.

References