Description
Caches can contain sensitive sessions, tokens and query results. ElastiCache encryption at rest protects data written to disk during synchronization, backup and swap operations, as well as backups. Memory access controls and encryption in transit require separate management.
For Terraform node-based replication groups, encryption at rest defaults to disabled for Redis OSS and enabled for Valkey. Omitting the setting therefore does not disable encryption for every engine.
Potential impact
Unauthorized acquisition of actually unencrypted stored data or backups can expose sensitive cached values. Organizational cache-encryption requirements may also be unmet.
Remediation
- Explicitly set
at_rest_encryption_enabled = truefor new replication groups and verify supported engines, node types and VPC configuration. - An existing node-based replication group’s encryption state cannot be changed. Plan any required backup and restore, then switch applications to a new encrypted group.
- Review Terraform replacement, restored data and connectivity. Manage encryption in transit, authentication and key permissions as well.
Examples
These are Redis OSS replication-group excerpts. Verify engine and node-type support in the Region, and configure the necessary VPC, subnets and security groups separately.
Before
resource "aws_elasticache_replication_group" "cache_cluster" {
automatic_failover_enabled = true
preferred_cache_cluster_azs = ["us-west-2a", "us-west-2b"]
replication_group_id = "tf-rep-group-1"
description = "test description"
node_type = "cache.m4.large"
num_cache_clusters = 2
port = 6379
}
This does not enable encryption at rest under the Redis OSS default.
After
resource "aws_elasticache_replication_group" "cache_cluster" {
automatic_failover_enabled = true
preferred_cache_cluster_azs = ["us-west-2a", "us-west-2b"]
replication_group_id = "tf-rep-group-1"
description = "test description"
node_type = "cache.m4.large"
num_cache_clusters = 2
port = 6379
at_rest_encryption_enabled = true
}
This requests encryption at rest for a new group. It does not automatically encrypt an existing group’s data, so prepare data migration and connection changes before replacement.