AWS ElastiCache replication group without encryption at rest

Encrypt ElastiCache data stored on disk and backups, and plan migration for existing groups.

Description

Caches can contain sensitive sessions, tokens and query results. ElastiCache encryption at rest protects data written to disk during synchronization, backup and swap operations, as well as backups. Memory access controls and encryption in transit require separate management.

For Terraform node-based replication groups, encryption at rest defaults to disabled for Redis OSS and enabled for Valkey. Omitting the setting therefore does not disable encryption for every engine.

Potential impact

Unauthorized acquisition of actually unencrypted stored data or backups can expose sensitive cached values. Organizational cache-encryption requirements may also be unmet.

Remediation

  • Explicitly set at_rest_encryption_enabled = true for new replication groups and verify supported engines, node types and VPC configuration.
  • An existing node-based replication group’s encryption state cannot be changed. Plan any required backup and restore, then switch applications to a new encrypted group.
  • Review Terraform replacement, restored data and connectivity. Manage encryption in transit, authentication and key permissions as well.

Examples

These are Redis OSS replication-group excerpts. Verify engine and node-type support in the Region, and configure the necessary VPC, subnets and security groups separately.

Before

hcl
resource "aws_elasticache_replication_group" "cache_cluster" {
  automatic_failover_enabled   = true
  preferred_cache_cluster_azs  = ["us-west-2a", "us-west-2b"]
  replication_group_id        = "tf-rep-group-1"
  description                 = "test description"
  node_type                   = "cache.m4.large"
  num_cache_clusters          = 2
  port                        = 6379
}

This does not enable encryption at rest under the Redis OSS default.

After

hcl
resource "aws_elasticache_replication_group" "cache_cluster" {
  automatic_failover_enabled   = true
  preferred_cache_cluster_azs  = ["us-west-2a", "us-west-2b"]
  replication_group_id        = "tf-rep-group-1"
  description                 = "test description"
  node_type                   = "cache.m4.large"
  num_cache_clusters          = 2
  port                        = 6379
  at_rest_encryption_enabled   = true
}

This requests encryption at rest for a new group. It does not automatically encrypt an existing group’s data, so prepare data migration and connection changes before replacement.

References