Customer managed KMS key not specified for a Serverless Framework function

Specify a customer managed KMS key when function environment variables require separate key control.

Description

Lambda environment variables are encrypted at rest by default. Setting kmsKeyArn in Serverless Framework selects a customer managed KMS key instead of the default key. Omitting it does not mean plaintext storage.

Potential impact

The configuration may not meet requirements for direct control of key policy or lifecycle.

Remediation

If a customer managed key is required, set provider.kmsKeyArn or the function’s kmsKeyArn to its ARN and check permissions. Review function overrides and manage actual secrets through services such as Secrets Manager.

Examples

The examples specify the same key at provider level and for hello. Repeating the same value on the function is unnecessary; replace the ARN with an actual key ARN. The KMS setting does not encrypt environment variable values in source files.

Before

yaml
provider:
  name: aws
  environment:
    TABLE_NAME: tableName1

functions:
  hello:
    handler: handler.hello
    environment:
      TABLE_NAME: tableName2

After

yaml
provider:
  name: aws
  kmsKeyArn: arn:aws:kms:us-east-1:111122223333:key/12345678-1234-1234-1234-123456789012
  environment:
    TABLE_NAME: tableName1

functions:
  hello:
    handler: handler.hello
    kmsKeyArn: arn:aws:kms:us-east-1:111122223333:key/12345678-1234-1234-1234-123456789012
    environment:
      TABLE_NAME: tableName2

References