Description
DAX is a DynamoDB caching layer, but its application data still needs protection. DAX encryption at rest protects data stored on disk; it does not replace protection of memory or encryption in transit.
Potential impact
Unauthorized acquisition of actually unencrypted storage can expose sensitive cached data. Organizational cache-encryption requirements may also be unmet.
Remediation
- Specify
server_side_encryption { enabled = true }for new clusters and reusable templates. - DAX encryption at rest is selected at creation and cannot be changed later. Replace an existing unencrypted cluster with a new encrypted cluster and plan application connection changes.
- Verify actual encryption, and review networking, access permissions and encryption in transit separately.
Examples
These are cluster excerpts. Supply the appropriate role, networking and a supported node type for the environment.
Before
hcl
resource "aws_dax_cluster" "dax_cluster" {
cluster_name = "cluster-example"
iam_role_arn = data.aws_iam_role.example.arn
node_type = "dax.r4.large"
replication_factor = 1
server_side_encryption {
enabled = false
}
}
This does not request encryption at rest.
After
hcl
resource "aws_dax_cluster" "dax_cluster" {
cluster_name = "cluster-example"
iam_role_arn = data.aws_iam_role.example.arn
node_type = "dax.r4.large"
replication_factor = 1
server_side_encryption {
enabled = true
}
}
This enables encryption at rest for a new cluster. Existing cluster data and connections are not migrated automatically.