Description
EFS commonly provides shared storage for multiple workloads, making protection of files, logs and application assets important. Encryption at rest protects file data and metadata.
An actually unencrypted file system lacks this layer of protection. File permissions, network access and TLS still require separate management.
Potential impact
Unauthorized acquisition of unencrypted storage can expose shared data and configuration files. Organizational file-storage encryption requirements may also be unmet.
Remediation
- Explicitly set
encrypted = truefor new EFS file systems and verify required KMS keys and permissions. - An existing file system’s encryption state cannot be changed. Create a new encrypted file system, copy data and switch mount targets and applications.
- Review Terraform replacement, verify data consistency, file access and backups, and preserve the original.
Examples
These are new-file-system excerpts. Configure mount targets and access permissions separately.
Before
resource "aws_efs_file_system" "shared_fs" {
creation_token = "my-product"
encrypted = false
}
This requests an unencrypted file system.
After
resource "aws_efs_file_system" "shared_fs" {
creation_token = "my-product"
encrypted = true
}
This requests a new encrypted file system. Applying it directly to an existing resource can replace that resource, so review data migration first.