Description
The Glue Data Catalog stores metadata and data-source connection information. Catalog encryption at rest and connection password protection are independent settings that need to be reviewed together.
Setting return_connection_password_encrypted = true keeps passwords encrypted in GetConnection and GetConnections responses. Enabling catalog encryption alone does not provide this protection. Catalog encryption can use an AWS managed KMS key when no customer managed key is specified.
Potential impact
Insufficient protection for metadata or connection passwords can expose sensitive values to someone who obtains stored information or query responses. Conversely, removing required KMS permissions or making a key unavailable can cause catalog reads and data-processing jobs to fail.
Remediation
- Choose a supported KMS encryption mode in
encryption_at_restand a key that meets organizational requirements. Specifysse_aws_kms_key_idwhen choosing a customer managed key. - Configure
return_connection_password_encrypted = trueand an appropriateaws_kms_key_idinconnection_password_encryption. Separate and minimize permissions for connection creation or updates and password decryption. - After the change, check the actual catalog, existing connections, responses and job operation. Manage encryption of the data source itself and TLS separately.
Examples
Prepare the referenced symmetric KMS key and required permissions separately. Both examples enable catalog encryption at rest; they differ only in whether passwords remain encrypted in responses.
Encrypted password responses disabled
resource "aws_glue_data_catalog_encryption_settings" "catalog_settings" {
data_catalog_encryption_settings {
connection_password_encryption {
aws_kms_key_id = aws_kms_key.test.arn
return_connection_password_encrypted = false
}
encryption_at_rest {
catalog_encryption_mode = "SSE-KMS"
sse_aws_kms_key_id = aws_kms_key.test.arn
}
}
}
This does not request that passwords remain encrypted in retrieval responses. It does not mean that the entire catalog is unencrypted.
Encrypted password responses enabled
resource "aws_glue_data_catalog_encryption_settings" "catalog_settings" {
data_catalog_encryption_settings {
connection_password_encryption {
aws_kms_key_id = aws_kms_key.test.arn
return_connection_password_encrypted = true
}
encryption_at_rest {
catalog_encryption_mode = "SSE-KMS"
sse_aws_kms_key_id = aws_kms_key.test.arn
}
}
}
This requests encrypted connection passwords in responses. Grant decryption permission on the key only to principals that actually need the passwords.