Amazon DocumentDB cluster without storage encryption

Encrypt DocumentDB stored data and backups, and plan migration of existing data.

Description

Document databases store customer information and core application data that need protection. DocumentDB storage encryption protects data, logs, automated backups and snapshots.

An actually unencrypted cluster lacks this layer of protection. Database permissions and network controls remain necessary with encryption enabled.

Potential impact

Unauthorized acquisition of unencrypted storage or backups can expose sensitive document data. Organizational storage-encryption requirements may also be unmet.

Remediation

  • Explicitly set storage_encrypted = true for new aws_docdb_cluster resources and select an appropriate default or customer managed key.
  • An existing unencrypted cluster cannot be encrypted directly. Plan an encrypted snapshot copy and restoration to a new cluster.
  • Review Terraform replacement, data consistency and connection cutover, then verify cluster and snapshot encryption and KMS permissions.

Examples

These are cluster-creation excerpts. Supply the password securely and protect Terraform state. Configure instances and networking separately, and review the omission of a final snapshot caused by skip_final_snapshot = true.

Before

hcl
resource "aws_docdb_cluster" "docdb_cluster" {
  cluster_identifier      = "my-docdb-cluster"
  engine                  = "docdb"
  master_username         = "foo"
  master_password         = var.docdb_password
  backup_retention_period = 5
  preferred_backup_window = "07:00-09:00"
  skip_final_snapshot     = true
}

This does not request storage encryption. Check the actual cluster state.

After

hcl
resource "aws_docdb_cluster" "docdb_cluster" {
  cluster_identifier      = "my-docdb-cluster"
  engine                  = "docdb"
  master_username         = "foo"
  master_password         = var.docdb_password
  backup_retention_period = 5
  preferred_backup_window = "07:00-09:00"
  skip_final_snapshot     = true
  storage_encrypted       = true
}

This requests storage encryption for a new cluster. Existing data is not encrypted or migrated automatically.

References