Description
DynamoDB can store application state, user data and session information. Tables are always encrypted at rest and use AWS owned keys by default.
In Terraform, server_side_encryption.enabled = false selects an AWS owned key rather than disabling encryption. With true and no kms_key_arn, it uses an AWS managed key. Specify an ARN separately for a customer managed key.
Potential impact
The default key may not meet organizational key-policy or lifecycle requirements. Loss of required key permissions can affect data access or recovery. Encryption does not replace permissions for tables or streams.
Remediation
- Select an AWS owned, AWS managed or customer managed key according to requirements.
- If a customer managed key is required, set
enabled = trueand its actualkms_key_arn, retaining necessary permissions. - Verify the actual key and normal data access afterward. Keep keys needed to restore existing backups available.
Examples
Both examples create encrypted tables; the key-management model differs.
AWS owned key
resource "aws_dynamodb_table" "orders_table" {
name = "example"
hash_key = "TestTableHashKey"
billing_mode = "PAY_PER_REQUEST"
stream_enabled = true
stream_view_type = "NEW_AND_OLD_IMAGES"
attribute {
name = "TestTableHashKey"
type = "S"
}
server_side_encryption {
enabled = false
}
}
This uses encryption with an AWS owned key.
AWS managed key
resource "aws_dynamodb_table" "orders_table" {
name = "example"
hash_key = "TestTableHashKey"
billing_mode = "PAY_PER_REQUEST"
stream_enabled = true
stream_view_type = "NEW_AND_OLD_IMAGES"
attribute {
name = "TestTableHashKey"
type = "S"
}
server_side_encryption {
enabled = true
}
}
This selects the default AWS managed KMS key. Specify a customer managed key ARN as well if the organization must manage the key policy itself.