Review the encryption key for a DynamoDB table

Distinguish default DynamoDB encryption from KMS key-management requirements

Description

DynamoDB encrypts stored table data by default. In Pulumi, serverSideEncryption.enabled = false selects an AWS owned key; it does not disable encryption. Choose a key that meets your organization’s key-management requirements.

Potential impact

An AWS owned key may not provide the key control and audit capabilities your organization requires.

Remediation

Set serverSideEncryption.enabled to true to use an AWS managed KMS key. For a customer managed key, also set kmsKeyArn and verify the key policy and usage permissions.

Examples

These excerpts switch from an AWS owned key to an AWS managed KMS key. Other required table settings are omitted.

Before

yaml
name: aws-eks
runtime: yaml
resources:
  example:
    type: aws:dynamodb:Table
    properties:
      serverSideEncryption:
        enabled: false

After

yaml
name: aws-eks
runtime: yaml
resources:
  example:
    type: aws:dynamodb:Table
    properties:
      serverSideEncryption:
        enabled: true

References