Description
When EBS encryption by default is disabled, new EBS volumes can be created unencrypted. Enabling it alongside per-volume encryption helps prevent configuration omissions.
This is a per-Region account setting, not an automatic change across all Regions. Individual volumes can still be encrypted when it is disabled, so check actual state.
Potential impact
Application data or logs can be stored unencrypted on new volumes whose encryption configuration is omitted. The same operational mistake can recur across teams and services.
Remediation
- Set
enabled = trueonaws_ebs_encryption_by_defaultin each relevant account and Region. - Verify the default KMS key, required permissions and instance support for encryption.
- Inventory existing unencrypted volumes and snapshots and plan any necessary migration. Changing the default does not retroactively encrypt existing data.
Examples
This setting applies to the account and Region selected by the AWS provider.
Before
resource "aws_ebs_encryption_by_default" "default_setting" {
enabled = false
}
This disables default encryption in that account and Region. It does not decrypt volumes that are already encrypted.
After
resource "aws_ebs_encryption_by_default" "default_setting" {
enabled = true
}
This applies default encryption to subsequently created EBS volumes and snapshot copies. Check existing data and other Regions separately.