Review EKS encryption key settings

Distinguish EKS default encryption from requirements for a customer managed KMS key.

Description

Kubernetes Secrets can contain sensitive tokens, passwords and certificates. EKS encrypts etcd storage disks for every cluster. On Kubernetes 1.28 and later, it also encrypts all API data by default using envelope encryption with an AWS owned key. Missing encryption_config therefore does not establish that data is stored in plaintext.

Configure a customer managed KMS key if your organization needs to control its key policy and lifecycle. This setting is separate from encryption of nodes and EBS volumes.

Potential impact

Using only the default key may not meet organizational requirements for customer managed keys. Deleting a key in use or removing required permissions can interrupt cluster operations and data access. Encryption does not replace Kubernetes access controls.

Remediation

  • Check the cluster version, actual encryption state and organizational key-management requirements.
  • If a customer managed key is required, prepare a suitable symmetric KMS key in the same Region and the necessary permissions. Specify its ARN and resources = ["secrets"] in encryption_config. On Kubernetes 1.28 and later, default envelope encryption covers all API data regardless of this list.
  • For an existing cluster, review the supported update procedure and Terraform plan, and control key disabling and deletion.

Examples

These excerpts show only encryption settings. Configure the required cluster role, VPC and subnets separately, and supply the actual KMS key ARN through the key variable.

Default encryption

hcl
resource "aws_eks_cluster" "eks_cluster" {
  name = var.cluster_name
}

On Kubernetes 1.28 and later, default envelope encryption applies without a separately configured customer managed key.

Specify a customer managed key

hcl
resource "aws_eks_cluster" "eks_cluster" {
  name = var.cluster_name

  encryption_config {
    resources = ["secrets"]

    provider {
      key_arn = var.eks_encryption_key_arn
    }
  }
}

This specifies the key required by the organization. Manage its key policy and cluster access permissions as well.

References