Review Glue Data Catalog and connection password encryption

Review Glue catalog encryption at rest and encrypted connection-password responses together.

Description

The Glue Data Catalog stores metadata and data-source connection information. Catalog encryption at rest and connection password protection are independent settings that need to be reviewed together.

Setting return_connection_password_encrypted = true keeps passwords encrypted in GetConnection and GetConnections responses. Enabling catalog encryption alone does not provide this protection. Catalog encryption can use an AWS managed KMS key when no customer managed key is specified.

Potential impact

Insufficient protection for metadata or connection passwords can expose sensitive values to someone who obtains stored information or query responses. Conversely, removing required KMS permissions or making a key unavailable can cause catalog reads and data-processing jobs to fail.

Remediation

  • Choose a supported KMS encryption mode in encryption_at_rest and a key that meets organizational requirements. Specify sse_aws_kms_key_id when choosing a customer managed key.
  • Configure return_connection_password_encrypted = true and an appropriate aws_kms_key_id in connection_password_encryption. Separate and minimize permissions for connection creation or updates and password decryption.
  • After the change, check the actual catalog, existing connections, responses and job operation. Manage encryption of the data source itself and TLS separately.

Examples

Prepare the referenced symmetric KMS key and required permissions separately. Both examples enable catalog encryption at rest; they differ only in whether passwords remain encrypted in responses.

Encrypted password responses disabled

hcl
resource "aws_glue_data_catalog_encryption_settings" "catalog_settings" {
  data_catalog_encryption_settings {
    connection_password_encryption {
      aws_kms_key_id                       = aws_kms_key.test.arn
      return_connection_password_encrypted = false
    }

    encryption_at_rest {
      catalog_encryption_mode = "SSE-KMS"
      sse_aws_kms_key_id      = aws_kms_key.test.arn
    }
  }
}

This does not request that passwords remain encrypted in retrieval responses. It does not mean that the entire catalog is unencrypted.

Encrypted password responses enabled

hcl
resource "aws_glue_data_catalog_encryption_settings" "catalog_settings" {
  data_catalog_encryption_settings {
    connection_password_encryption {
      aws_kms_key_id                       = aws_kms_key.test.arn
      return_connection_password_encrypted = true
    }

    encryption_at_rest {
      catalog_encryption_mode = "SSE-KMS"
      sse_aws_kms_key_id      = aws_kms_key.test.arn
    }
  }
}

This requests encrypted connection passwords in responses. Grant decryption permission on the key only to principals that actually need the passwords.

References