AWS EFS file system without encryption

Protect EFS file data and metadata with encryption at rest.

Description

EFS commonly provides shared storage for multiple workloads, making protection of files, logs and application assets important. Encryption at rest protects file data and metadata.

An actually unencrypted file system lacks this layer of protection. File permissions, network access and TLS still require separate management.

Potential impact

Unauthorized acquisition of unencrypted storage can expose shared data and configuration files. Organizational file-storage encryption requirements may also be unmet.

Remediation

  • Explicitly set encrypted = true for new EFS file systems and verify required KMS keys and permissions.
  • An existing file system’s encryption state cannot be changed. Create a new encrypted file system, copy data and switch mount targets and applications.
  • Review Terraform replacement, verify data consistency, file access and backups, and preserve the original.

Examples

These are new-file-system excerpts. Configure mount targets and access permissions separately.

Before

hcl
resource "aws_efs_file_system" "shared_fs" {
  creation_token = "my-product"
  encrypted      = false
}

This requests an unencrypted file system.

After

hcl
resource "aws_efs_file_system" "shared_fs" {
  creation_token = "my-product"
  encrypted      = true
}

This requests a new encrypted file system. Applying it directly to an existing resource can replace that resource, so review data migration first.

References