Review automatic rotation of Alicloud KMS keys

Configure automatic rotation and an appropriate interval for supported keys.

Description

KMS automatic rotation creates a new key version to limit how long the same key material is used. Enable it for supported symmetric keys and choose an interval of 7–365 days that meets organizational requirements.

Potential impact

Disabled rotation or an interval longer than policy permits can keep the same key material in use beyond its intended lifetime.

Remediation

Set automatic_rotation = "Enabled" and a suitable rotation_interval for supported keys. Establish a separate replacement process for imported key material or unsupported key types.

Examples

The examples enable automatic rotation. Seven days is illustrative; rotation does not re-encrypt existing ciphertext.

Before

hcl
resource "alicloud_kms_key" "key" {
  description            = "Hello KMS"
  pending_window_in_days = "7"
  status                 = "Enabled"
  automatic_rotation     = "Disabled"
}

After

hcl
resource "alicloud_kms_key" "key" {
  description            = "Hello KMS"
  pending_window_in_days = "7"
  status                 = "Enabled"
  automatic_rotation     = "Enabled"
  rotation_interval      = "7d"
}

References