Description
Document databases store customer information and core application data that need protection. DocumentDB storage encryption protects data, logs, automated backups and snapshots.
An actually unencrypted cluster lacks this layer of protection. Database permissions and network controls remain necessary with encryption enabled.
Potential impact
Unauthorized acquisition of unencrypted storage or backups can expose sensitive document data. Organizational storage-encryption requirements may also be unmet.
Remediation
- Explicitly set
storage_encrypted = truefor newaws_docdb_clusterresources and select an appropriate default or customer managed key. - An existing unencrypted cluster cannot be encrypted directly. Plan an encrypted snapshot copy and restoration to a new cluster.
- Review Terraform replacement, data consistency and connection cutover, then verify cluster and snapshot encryption and KMS permissions.
Examples
These are cluster-creation excerpts. Supply the password securely and protect Terraform state. Configure instances and networking separately, and review the omission of a final snapshot caused by skip_final_snapshot = true.
Before
resource "aws_docdb_cluster" "docdb_cluster" {
cluster_identifier = "my-docdb-cluster"
engine = "docdb"
master_username = "foo"
master_password = var.docdb_password
backup_retention_period = 5
preferred_backup_window = "07:00-09:00"
skip_final_snapshot = true
}
This does not request storage encryption. Check the actual cluster state.
After
resource "aws_docdb_cluster" "docdb_cluster" {
cluster_identifier = "my-docdb-cluster"
engine = "docdb"
master_username = "foo"
master_password = var.docdb_password
backup_retention_period = 5
preferred_backup_window = "07:00-09:00"
skip_final_snapshot = true
storage_encrypted = true
}
This requests storage encryption for a new cluster. Existing data is not encrypted or migrated automatically.