DocumentDB encryption key settings need review

Distinguish DocumentDB’s default KMS key from customer managed key requirements.

Description

When DocumentDB storage encryption is enabled without kms_key_id, it uses the service’s default AWS managed KMS key. Omitting the identifier does not mean KMS encryption is absent.

Specify a customer managed key when the organization needs its own key policies and lifecycle control. Verify required permissions and actual encryption regardless of the key selected.

Potential impact

The default key may not meet organizational key-management requirements. Removing required permissions or making a key unavailable can interrupt data access and recovery.

Remediation

  • For new clusters, set storage_encrypted = true together with a customer managed kms_key_id when required. The default key may be used if it meets organizational requirements.
  • Select a usable key in the same Region and limit key permissions to what is needed.
  • An existing cluster’s key cannot be changed directly. Review restoration of a snapshot copy encrypted with the required key into a new cluster, along with the Terraform replacement plan.

Examples

These are creation excerpts. Supply the password securely and protect Terraform state. Configure instances, networking and backups separately, and review the example’s skip_final_snapshot = true against operational requirements.

Default AWS managed key

hcl
resource "aws_docdb_cluster" "docdb_cluster" {
  cluster_identifier      = "my-docdb-cluster"
  engine                  = "docdb"
  master_username         = "foo"
  master_password         = var.docdb_password
  backup_retention_period = 5
  preferred_backup_window = "07:00-09:00"
  skip_final_snapshot     = true
  storage_encrypted       = true
}

This enables encryption with the default KMS key. Check whether separate key control is required.

Customer managed key

hcl
resource "aws_docdb_cluster" "docdb_cluster" {
  cluster_identifier      = "my-docdb-cluster"
  engine                  = "docdb"
  master_username         = "foo"
  master_password         = var.docdb_password
  backup_retention_period = 5
  preferred_backup_window = "07:00-09:00"
  skip_final_snapshot     = true
  storage_encrypted       = true
  kms_key_id              = "arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab"
}

Replace the example ARN with an actual approved key ARN. This setting alone does not migrate an existing cluster to a new key.

References