Description
Search domains can store logs, operational data and application indexes. Check that encryption at rest and the key in use meet organizational requirements.
With encrypt_at_rest enabled, omitting kms_key_id uses the default aws/es service KMS key according to the Terraform AWS provider v6.14.0 documentation. A missing key identifier does not mean that encryption is absent. Choose a customer managed key if the organization needs direct control over key policy and lifecycle.
Potential impact
The default key alone may not meet organizational separation-of-duties or key-management requirements. Conversely, disabling or deleting a key in use can make domain data inaccessible. Key selection does not replace data access policies or network controls.
Remediation
- Check the actual encryption state and key. If a customer managed key is required, specify an approved symmetric KMS key ARN in
kms_key_idand grant the permissions required by the service. - An encrypted domain’s key cannot be directly switched to another key. Review Terraform resource replacement and data migration, preserving the original data and recovery options.
- Restrict key disabling and deletion, and verify required data access and recovery.
Examples
These are encryption-setting excerpts. Choose an Elasticsearch version of 5.1 or later and an instance type that support encryption for new domains. Configure required storage, access policies and networking separately, and supply the actual key ARN through the key variable.
Use the default service key
resource "aws_elasticsearch_domain" "search_domain" {
domain_name = "example"
elasticsearch_version = var.elasticsearch_version
encrypt_at_rest {
enabled = true
}
}
This enables encryption at rest with the default service key. It is not an unencrypted example.
Specify a customer managed key
resource "aws_elasticsearch_domain" "search_domain" {
domain_name = "example"
elasticsearch_version = var.elasticsearch_version
encrypt_at_rest {
enabled = true
kms_key_id = var.encryption_key_arn
}
}
This specifies a key for a new domain. Applying it directly to an existing domain does not simply replace the key while preserving the data.