Description
EBS volumes can store application data, logs, temporary files and operational assets. Encryption at rest protects volumes and snapshots made from their data.
Actual encryption also depends on source snapshots and regional EBS encryption defaults. Verify state rather than infer that a volume is unencrypted solely from an omitted encrypted setting or false.
Potential impact
Unauthorized acquisition of unencrypted volumes or snapshots can expose sensitive information. Some volumes may remain outside organizational encryption requirements.
Remediation
- Set
encrypted = truefor new volumes and reusable creation modules or templates. - Verify the required KMS permissions and actual encryption of created volumes.
- Migrate an existing unencrypted volume through an encrypted snapshot copy and a new volume. Review Terraform replacement, data consistency and instance attachments, preserving the original until verification is complete.
Examples
These are volume-creation excerpts. The Availability Zone must match the instance that will use the volume; attachment configuration is separate.
Before
resource "aws_ebs_volume" "app_data_volume" {
availability_zone = "us-west-2a"
size = 40
encrypted = false
}
This does not explicitly request volume encryption. Check actual encryption, including regional defaults.
After
resource "aws_ebs_volume" "app_data_volume" {
availability_zone = "us-west-2a"
size = 40
encrypted = true
}
This requests encryption for a new volume. The flag alone does not encrypt an existing volume.