Description
When DocumentDB storage encryption is enabled without kms_key_id, it uses the service’s default AWS managed KMS key. Omitting the identifier does not mean KMS encryption is absent.
Specify a customer managed key when the organization needs its own key policies and lifecycle control. Verify required permissions and actual encryption regardless of the key selected.
Potential impact
The default key may not meet organizational key-management requirements. Removing required permissions or making a key unavailable can interrupt data access and recovery.
Remediation
- For new clusters, set
storage_encrypted = truetogether with a customer managedkms_key_idwhen required. The default key may be used if it meets organizational requirements. - Select a usable key in the same Region and limit key permissions to what is needed.
- An existing cluster’s key cannot be changed directly. Review restoration of a snapshot copy encrypted with the required key into a new cluster, along with the Terraform replacement plan.
Examples
These are creation excerpts. Supply the password securely and protect Terraform state. Configure instances, networking and backups separately, and review the example’s skip_final_snapshot = true against operational requirements.
Default AWS managed key
resource "aws_docdb_cluster" "docdb_cluster" {
cluster_identifier = "my-docdb-cluster"
engine = "docdb"
master_username = "foo"
master_password = var.docdb_password
backup_retention_period = 5
preferred_backup_window = "07:00-09:00"
skip_final_snapshot = true
storage_encrypted = true
}
This enables encryption with the default KMS key. Check whether separate key control is required.
Customer managed key
resource "aws_docdb_cluster" "docdb_cluster" {
cluster_identifier = "my-docdb-cluster"
engine = "docdb"
master_username = "foo"
master_password = var.docdb_password
backup_retention_period = 5
preferred_backup_window = "07:00-09:00"
skip_final_snapshot = true
storage_encrypted = true
kms_key_id = "arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab"
}
Replace the example ARN with an actual approved key ARN. This setting alone does not migrate an existing cluster to a new key.