Description
Athena datasets and query results can contain customer information, logs and internal operational data. Manage encryption and permissions for result locations according to organizational requirements.
The encryption_configuration on aws_athena_database configures results for its database-creation and deletion queries. It does not protect all source S3 data, Glue metadata or subsequent queries. S3 also encrypts new objects by default, so omitting this block does not establish plaintext storage.
Potential impact
The required KMS key or key policy may not apply, leaving key-management requirements unmet. Excessive permissions to result files can expose sensitive data even when encryption is enabled.
Remediation
- Verify the actual output location and encryption. If a customer managed key is required, configure
SSE_KMSwith a usable KMS key ARN. - Configure a workgroup and its client-setting override to apply the same requirements to subsequent queries. Review source data and Glue metadata separately.
- Limit KMS and S3 permissions. Inspect the Terraform plan before changing encryption settings, which can recreate the database resource.
Examples
These excerpts reference a separately defined S3 bucket and KMS key. A workgroup that overrides client settings takes precedence for result configuration.
Separate encryption configuration omitted
resource "aws_athena_database" "analytics_db" {
name = "database_name"
bucket = aws_s3_bucket.hoge.bucket
}
This resource does not select a separate result-encryption method. Check actual S3 defaults and workgroup settings.
Result encryption key selected
resource "aws_athena_database" "analytics_db" {
name = "database_name"
bucket = aws_s3_bucket.hoge.bucket
encryption_configuration {
encryption_option = "SSE_KMS"
kms_key = aws_kms_key.example.arn
}
}
This selects a KMS key for the result configuration. It does not automatically re-encrypt existing data or every subsequent query’s results.