Description
Aurora stores core application data and customer information. Encryption at rest protects data, backups and snapshots, so verify the actual encryption state and key.
New Aurora clusters created on or after February 18, 2026 are encrypted with AWS owned keys by default. A missing explicit option does not mean plaintext storage. Data restored or cloned from older unencrypted snapshots can remain unencrypted.
Potential impact
Unauthorized access to actually unencrypted storage or backups can expose sensitive information or leave organizational encryption requirements unmet. Database permissions and network controls are still necessary with encryption enabled.
Remediation
- Explicitly set
storage_encrypted = truefor new clusters and apply the required key-management controls. - For an existing unencrypted cluster, plan an encrypted snapshot copy and restoration to a new cluster. Verify data consistency and application cutover.
- Inspect the Terraform plan for replacement, then verify actual cluster and backup encryption and KMS permissions.
Examples
These are cluster excerpts. Supply the password securely and restrict access to Terraform state. Database instances, networking and other required configuration are separate.
No explicit encryption request
resource "aws_rds_cluster" "aurora_cluster" {
cluster_identifier = "my-cluster"
engine = "aurora-mysql"
master_username = "admin"
master_password = var.master_password
storage_encrypted = false
}
This does not explicitly request encryption. Verify actual state according to current service defaults and the creation or restoration path.
Explicit encryption request
resource "aws_rds_cluster" "aurora_cluster" {
cluster_identifier = "my-cluster"
engine = "aurora-mysql"
master_username = "admin"
master_password = var.master_password
storage_encrypted = true
}
This requests encryption for a new cluster; it does not automatically migrate existing unencrypted data.