Description
Athena query results can contain table data, aggregates and internal analysis. Workgroups using an S3 result location should apply consistent result-encryption and key-management requirements.
S3 encrypts new objects by default, so omitting a workgroup encryption block does not mean plaintext storage. If a customer managed key is required, specify it and enforce workgroup settings so clients cannot override that requirement.
Potential impact
Per-user output locations or keys may not meet organizational protection requirements. Even with encryption enabled, excessive permissions to result files must be restricted separately.
Remediation
- Set the required
encryption_configurationwithinresult_configuration. For a customer managed key, useSSE_KMSand its actualkms_key_arn. - Set
enforce_workgroup_configuration = trueand review the impact of output-location and key changes on existing automation. - Limit S3 and KMS permissions, then verify actual result encryption and access with a test query. Review source data and existing result files separately.
Examples
Define the referenced bucket and key separately.
Separate result-encryption configuration omitted
resource "aws_athena_workgroup" "analytics_wg" {
name = "example"
configuration {
enforce_workgroup_configuration = true
publish_cloudwatch_metrics_enabled = true
result_configuration {
output_location = "s3://${aws_s3_bucket.example.bucket}/output/"
}
}
}
This specifies an output location without selecting a separate encryption method. Check the bucket’s effective encryption against organizational requirements.
Result encryption key and enforcement configured
resource "aws_athena_workgroup" "analytics_wg" {
name = "example"
configuration {
enforce_workgroup_configuration = true
publish_cloudwatch_metrics_enabled = true
result_configuration {
output_location = "s3://${aws_s3_bucket.example.bucket}/output/"
encryption_configuration {
encryption_option = "SSE_KMS"
kms_key_arn = aws_kms_key.example.arn
}
}
}
}
Queries in this workgroup use the specified result location and KMS encryption. This change does not automatically re-encrypt existing result files.