Review Glue Security Configuration encryption settings

Check encryption modes for Glue logs, bookmarks and results, and that the security configuration is applied.

Description

Glue jobs write logs, job bookmarks and results to multiple stores. Attach a Security Configuration to the actual job or crawler and choose encryption modes and keys that meet organizational requirements. Creating the configuration resource alone does not apply it to every job.

CloudWatch Logs and new S3 objects provide default encryption at rest, so a missing Glue KMS setting does not establish plaintext storage. S3 also supports SSE-S3; assess the need for a customer managed key separately.

Potential impact

Encryption modes or keys that do not meet requirements can leave organizational key-control requirements unmet for job data. Missing KMS permissions or unavailable keys can cause logging, data processing or recovery to fail. Encryption does not replace access controls for logs and results.

Remediation

  • For CloudWatch logs that require KMS, specify cloudwatch_encryption_mode = "SSE-KMS" and an appropriate kms_key_arn.
  • If job bookmarks require additional client-side encryption, configure job_bookmarks_encryption_mode = "CSE-KMS" and a key. Choose SSE-KMS or SSE-S3 for S3 according to requirements.
  • Check key permissions for the jobs, crawlers and services using the configuration. After a real run, verify encryption and read access for logs, bookmarks and result objects.

Examples

Prepare the referenced symmetric KMS key and permissions separately. These configurations must also be attached to the job or crawler that uses them.

Log key not specified

hcl
resource "aws_glue_security_configuration" "glue_security" {
  name = "example"

  encryption_configuration {
    cloudwatch_encryption {
      cloudwatch_encryption_mode = "SSE-KMS"
    }

    job_bookmarks_encryption {
      job_bookmarks_encryption_mode = "CSE-KMS"
      kms_key_arn                   = data.aws_kms_key.example.arn
    }

    s3_encryption {
      kms_key_arn        = data.aws_kms_key.example.arn
      s3_encryption_mode = "SSE-KMS"
    }
  }
}

This selects KMS encryption for CloudWatch logs without specifying the key to use. This setting alone does not show that logs are stored in plaintext.

Log key specified

hcl
resource "aws_glue_security_configuration" "glue_security" {
  name = "example"

  encryption_configuration {
    cloudwatch_encryption {
      cloudwatch_encryption_mode = "SSE-KMS"
      kms_key_arn                = data.aws_kms_key.example.arn
    }

    job_bookmarks_encryption {
      job_bookmarks_encryption_mode = "CSE-KMS"
      kms_key_arn                   = data.aws_kms_key.example.arn
    }

    s3_encryption {
      kms_key_arn        = data.aws_kms_key.example.arn
      s3_encryption_mode = "SSE-KMS"
    }
  }
}

This specifies KMS keys for logs, job bookmarks and S3 results. Verify key policies and that the configuration is actually applied.

References