Description
Lambda environment variables are encrypted at rest by default. Setting kmsKeyArn in Serverless Framework selects a customer managed KMS key instead of the default key. Omitting it does not mean plaintext storage.
Potential impact
The configuration may not meet requirements for direct control of key policy or lifecycle.
Remediation
If a customer managed key is required, set provider.kmsKeyArn or the function’s kmsKeyArn to its ARN and check permissions. Review function overrides and manage actual secrets through services such as Secrets Manager.
Examples
The examples specify the same key at provider level and for hello. Repeating the same value on the function is unnecessary; replace the ARN with an actual key ARN. The KMS setting does not encrypt environment variable values in source files.
Before
provider:
name: aws
environment:
TABLE_NAME: tableName1
functions:
hello:
handler: handler.hello
environment:
TABLE_NAME: tableName2
After
provider:
name: aws
kmsKeyArn: arn:aws:kms:us-east-1:111122223333:key/12345678-1234-1234-1234-123456789012
environment:
TABLE_NAME: tableName1
functions:
hello:
handler: handler.hello
kmsKeyArn: arn:aws:kms:us-east-1:111122223333:key/12345678-1234-1234-1234-123456789012
environment:
TABLE_NAME: tableName2