Description
A disabled KMS key cannot perform cryptographic operations such as encryption and decryption. Services that need it can fail. Disabling a key may also be intentional incident containment or preparation for retirement, so check its purpose and the reason it was disabled.
Potential impact
- Data reads, writes, or service startup requiring the key can fail.
- Multiple resources using the same key can widen the disruption.
Remediation
Review dependent resources and the reason for disabling the key. Apply is_enabled = true only to keys approved for continued use. For intentional retirement, follow the required service migration or decommissioning plan. Check key policies and usage permissions after enabling it.
Examples
These examples re-enable a key that must remain in use. Disabling is different from deleting; the example does not recommend enabling every disabled key.
Before
resource "aws_kms_key" "example" {
description = "KMS key 1"
is_enabled = false
}
After
resource "aws_kms_key" "example" {
description = "KMS key 1"
is_enabled = true
}
The revision restores the key to an enabled state. Operations still need appropriate permissions as well as a usable key state.