Description
Search domains can store logs, document indexes and operational data that need encryption at rest. With encryption disabled, indexes and related stored data lack this protective layer.
Encryption at rest protects domain data and automated snapshots. Manual snapshot repositories, logs exported to CloudWatch and data in transit require separate protection.
Potential impact
Unauthorized acquisition of unencrypted stored data or backups can expose sensitive documents and logs. Organizational search-service encryption requirements may also be unmet.
Remediation
- Set
enabled = trueinencrypt_at_rest. If a customer managed key is required, specify an approved key ARN inkms_key_id. - New domains require Elasticsearch 5.1 or later and an instance type that supports encryption. Encryption can be enabled on existing domains running 6.7 or later; on earlier versions, Terraform can replace the domain, so plan data migration first.
- Review the change plan and service constraints. Verify actual encryption, key permissions, snapshot recovery and client connectivity, preserving original data and recovery options.
Examples
These encryption-setting excerpts take a supported version as an input. Configure required instances, storage, access policies and networking separately.
Before
resource "aws_elasticsearch_domain" "search_domain" {
domain_name = "example"
elasticsearch_version = var.elasticsearch_version
encrypt_at_rest {
enabled = false
}
}
This disables domain encryption at rest.
After
resource "aws_elasticsearch_domain" "search_domain" {
domain_name = "example"
elasticsearch_version = var.elasticsearch_version
encrypt_at_rest {
enabled = true
}
}
This enables encryption at rest. Omitting the key uses the default service KMS key, so review any customer managed key requirement separately.