Description
A customer managed KMS key lets your organization control the key policy and lifecycle for EFS. An encrypted file system can use an AWS managed key when no customer key is specified, so an omitted key setting does not establish that storage is unencrypted.
Encryption at rest does not replace file permissions or TLS for mount connections.
Potential impact
- The default key may not meet organizational controls that require a customer managed key.
- An actually unencrypted file system lacks protection from encryption at rest. Disabling or deleting a key in use can instead interrupt file access.
Remediation
Set encrypted: true for a new file system and, where a customer key is required, specify an available key in the same Region through kmsKeyID. Check the key policy and necessary permissions. An existing file system’s encryption state and KMS key cannot be changed; plan and verify data migration and mount cutover to a new file system.
Examples
Use a key ID and provider configuration appropriate for your environment.
Before
apiVersion: efs.aws.crossplane.io/v1alpha1
kind: FileSystem
metadata:
name: example
spec:
forProvider:
region: us-east-1
encrypted: false
providerConfigRef:
name: example
This does not request encryption at rest for the new file system.
After
apiVersion: efs.aws.crossplane.io/v1alpha1
kind: FileSystem
metadata:
name: example
spec:
forProvider:
region: us-east-1
kmsKeyID: 1234abcd-12ab-34cd-56ef-1234567890ab
encrypted: true
providerConfigRef:
name: example
This requests a new file system encrypted with the specified KMS key. It does not automatically migrate data from an existing resource.