Athena workgroup result encryption settings need review

Verify Athena workgroup result encryption and which settings take precedence.

Description

Athena query results can contain table data, aggregates and internal analysis. Workgroups using an S3 result location should apply consistent result-encryption and key-management requirements.

S3 encrypts new objects by default, so omitting a workgroup encryption block does not mean plaintext storage. If a customer managed key is required, specify it and enforce workgroup settings so clients cannot override that requirement.

Potential impact

Per-user output locations or keys may not meet organizational protection requirements. Even with encryption enabled, excessive permissions to result files must be restricted separately.

Remediation

  • Set the required encryption_configuration within result_configuration. For a customer managed key, use SSE_KMS and its actual kms_key_arn.
  • Set enforce_workgroup_configuration = true and review the impact of output-location and key changes on existing automation.
  • Limit S3 and KMS permissions, then verify actual result encryption and access with a test query. Review source data and existing result files separately.

Examples

Define the referenced bucket and key separately.

Separate result-encryption configuration omitted

hcl
resource "aws_athena_workgroup" "analytics_wg" {
  name = "example"

  configuration {
    enforce_workgroup_configuration    = true
    publish_cloudwatch_metrics_enabled = true

    result_configuration {
      output_location = "s3://${aws_s3_bucket.example.bucket}/output/"
    }
  }
}

This specifies an output location without selecting a separate encryption method. Check the bucket’s effective encryption against organizational requirements.

Result encryption key and enforcement configured

hcl
resource "aws_athena_workgroup" "analytics_wg" {
  name = "example"

  configuration {
    enforce_workgroup_configuration    = true
    publish_cloudwatch_metrics_enabled = true

    result_configuration {
      output_location = "s3://${aws_s3_bucket.example.bucket}/output/"

      encryption_configuration {
        encryption_option = "SSE_KMS"
        kms_key_arn       = aws_kms_key.example.arn
      }
    }
  }
}

Queries in this workgroup use the specified result location and KMS encryption. This change does not automatically re-encrypt existing result files.

References