AWS EBS volume without encryption

Verify actual EBS volume encryption and safely migrate existing unencrypted data.

Description

EBS volumes can store application data, logs, temporary files and operational assets. Encryption at rest protects volumes and snapshots made from their data.

Actual encryption also depends on source snapshots and regional EBS encryption defaults. Verify state rather than infer that a volume is unencrypted solely from an omitted encrypted setting or false.

Potential impact

Unauthorized acquisition of unencrypted volumes or snapshots can expose sensitive information. Some volumes may remain outside organizational encryption requirements.

Remediation

  • Set encrypted = true for new volumes and reusable creation modules or templates.
  • Verify the required KMS permissions and actual encryption of created volumes.
  • Migrate an existing unencrypted volume through an encrypted snapshot copy and a new volume. Review Terraform replacement, data consistency and instance attachments, preserving the original until verification is complete.

Examples

These are volume-creation excerpts. The Availability Zone must match the instance that will use the volume; attachment configuration is separate.

Before

hcl
resource "aws_ebs_volume" "app_data_volume" {
  availability_zone = "us-west-2a"
  size              = 40
  encrypted         = false
}

This does not explicitly request volume encryption. Check actual encryption, including regional defaults.

After

hcl
resource "aws_ebs_volume" "app_data_volume" {
  availability_zone = "us-west-2a"
  size              = 40
  encrypted         = true
}

This requests encryption for a new volume. The flag alone does not encrypt an existing volume.

References