DynamoDB table encryption key settings need review

Check DynamoDB default encryption and the required KMS key-management model.

Description

DynamoDB can store application state, user data and session information. Tables are always encrypted at rest and use AWS owned keys by default.

In Terraform, server_side_encryption.enabled = false selects an AWS owned key rather than disabling encryption. With true and no kms_key_arn, it uses an AWS managed key. Specify an ARN separately for a customer managed key.

Potential impact

The default key may not meet organizational key-policy or lifecycle requirements. Loss of required key permissions can affect data access or recovery. Encryption does not replace permissions for tables or streams.

Remediation

  • Select an AWS owned, AWS managed or customer managed key according to requirements.
  • If a customer managed key is required, set enabled = true and its actual kms_key_arn, retaining necessary permissions.
  • Verify the actual key and normal data access afterward. Keep keys needed to restore existing backups available.

Examples

Both examples create encrypted tables; the key-management model differs.

AWS owned key

hcl
resource "aws_dynamodb_table" "orders_table" {
  name             = "example"
  hash_key         = "TestTableHashKey"
  billing_mode     = "PAY_PER_REQUEST"
  stream_enabled   = true
  stream_view_type = "NEW_AND_OLD_IMAGES"

  attribute {
    name = "TestTableHashKey"
    type = "S"
  }

  server_side_encryption {
    enabled = false
  }
}

This uses encryption with an AWS owned key.

AWS managed key

hcl
resource "aws_dynamodb_table" "orders_table" {
  name             = "example"
  hash_key         = "TestTableHashKey"
  billing_mode     = "PAY_PER_REQUEST"
  stream_enabled   = true
  stream_view_type = "NEW_AND_OLD_IMAGES"

  attribute {
    name = "TestTableHashKey"
    type = "S"
  }

  server_side_encryption {
    enabled = true
  }
}

This selects the default AWS managed KMS key. Specify a customer managed key ARN as well if the organization must manage the key policy itself.

References