Amazon Aurora storage encryption settings need review

Verify actual Aurora storage encryption and keys, and protect existing unencrypted data.

Description

Aurora stores core application data and customer information. Encryption at rest protects data, backups and snapshots, so verify the actual encryption state and key.

New Aurora clusters created on or after February 18, 2026 are encrypted with AWS owned keys by default. A missing explicit option does not mean plaintext storage. Data restored or cloned from older unencrypted snapshots can remain unencrypted.

Potential impact

Unauthorized access to actually unencrypted storage or backups can expose sensitive information or leave organizational encryption requirements unmet. Database permissions and network controls are still necessary with encryption enabled.

Remediation

  • Explicitly set storage_encrypted = true for new clusters and apply the required key-management controls.
  • For an existing unencrypted cluster, plan an encrypted snapshot copy and restoration to a new cluster. Verify data consistency and application cutover.
  • Inspect the Terraform plan for replacement, then verify actual cluster and backup encryption and KMS permissions.

Examples

These are cluster excerpts. Supply the password securely and restrict access to Terraform state. Database instances, networking and other required configuration are separate.

No explicit encryption request

hcl
resource "aws_rds_cluster" "aurora_cluster" {
  cluster_identifier       = "my-cluster"
  engine                   = "aurora-mysql"
  master_username          = "admin"
  master_password          = var.master_password
  storage_encrypted        = false
}

This does not explicitly request encryption. Verify actual state according to current service defaults and the creation or restoration path.

Explicit encryption request

hcl
resource "aws_rds_cluster" "aurora_cluster" {
  cluster_identifier       = "my-cluster"
  engine                   = "aurora-mysql"
  master_username          = "admin"
  master_password          = var.master_password
  storage_encrypted        = true
}

This requests encryption for a new cluster; it does not automatically migrate existing unencrypted data.

References