Description
Backups are recovery assets and copies of sensitive data. A snapshot created from an EBS volume inherits the actual source volume’s encryption state. An unencrypted snapshot lacks encryption-at-rest protection.
Regional encryption defaults can affect the source volume’s actual state. Check both the volume and snapshot rather than rely on the template alone.
Potential impact
Unauthorized acquisition or inappropriate sharing of unencrypted backups can expose application data and sensitive information. Encrypted snapshots also require restricted sharing and KMS permissions.
Remediation
- Explicitly set
encrypted = truefor new source EBS volumes and verify actual volume and snapshot encryption. - Create encrypted copies of existing unencrypted snapshots. The original snapshot cannot be encrypted directly.
- Test recovery and data consistency, retaining originals until verified. Plan replacement and attachment changes separately when migrating existing volumes.
Examples
These examples create a new volume and snapshot. For backups of active volumes, also ensure application-data consistency.
Before
resource "aws_ebs_volume" "source_volume" {
availability_zone = "us-west-2a"
size = 40
encrypted = false
}
resource "aws_ebs_snapshot" "snapshot" {
volume_id = aws_ebs_volume.source_volume.id
}
The source volume does not explicitly request encryption. If it is actually unencrypted, this snapshot is also unencrypted.
After
resource "aws_ebs_volume" "source_volume" {
availability_zone = "us-west-2a"
size = 40
encrypted = true
}
resource "aws_ebs_snapshot" "snapshot" {
volume_id = aws_ebs_volume.source_volume.id
}
This creates an encrypted snapshot from a new encrypted volume. It does not encrypt an existing snapshot.