Description
KMS rotation reduces prolonged use of the same key material. Automatic rotation must be used with supported configurations, such as symmetric encryption keys generated by KMS. The key ARN and access policy remain unchanged; rotation alone neither re-encrypts existing data nor revokes a compromised principal’s permissions.
Potential impact
- Missing required rotation can violate the organization’s key-material lifetime policy.
- Treating rotation as revocation or data re-encryption can leave incident-response work incomplete.
Remediation
Check the key type and origin, and set enable_key_rotation = true where required for customer managed keys that support automatic rotation. Plan an appropriate replacement process for unsupported key types. Maintain key policies and a usage inventory, and revoke compromised permissions separately.
Examples
These examples compare automatic rotation for the default KMS-generated symmetric encryption key. Do not apply the setting indiscriminately to other key types.
Before
resource "aws_kms_key" "example" {
description = "KMS key 2"
is_enabled = true
enable_key_rotation = false
}
After
resource "aws_kms_key" "example" {
description = "KMS key 1"
is_enabled = true
enable_key_rotation = true
}
The revision enables automatic rotation. KMS retains older key material to decrypt data encrypted with it. The description-string change does not affect rotation.