AWS DAX cluster without encryption at rest

Encrypt data stored on disk by DAX clusters.

Description

DAX is a DynamoDB caching layer, but its application data still needs protection. DAX encryption at rest protects data stored on disk; it does not replace protection of memory or encryption in transit.

Potential impact

Unauthorized acquisition of actually unencrypted storage can expose sensitive cached data. Organizational cache-encryption requirements may also be unmet.

Remediation

  • Specify server_side_encryption { enabled = true } for new clusters and reusable templates.
  • DAX encryption at rest is selected at creation and cannot be changed later. Replace an existing unencrypted cluster with a new encrypted cluster and plan application connection changes.
  • Verify actual encryption, and review networking, access permissions and encryption in transit separately.

Examples

These are cluster excerpts. Supply the appropriate role, networking and a supported node type for the environment.

Before

hcl
resource "aws_dax_cluster" "dax_cluster" {
  cluster_name       = "cluster-example"
  iam_role_arn       = data.aws_iam_role.example.arn
  node_type          = "dax.r4.large"
  replication_factor = 1

  server_side_encryption {
    enabled = false
  }
}

This does not request encryption at rest.

After

hcl
resource "aws_dax_cluster" "dax_cluster" {
  cluster_name       = "cluster-example"
  iam_role_arn       = data.aws_iam_role.example.arn
  node_type          = "dax.r4.large"
  replication_factor = 1

  server_side_encryption {
    enabled = true
  }
}

This enables encryption at rest for a new cluster. Existing cluster data and connections are not migrated automatically.

References