Description
Glue jobs write logs, job bookmarks and results to multiple stores. Attach a Security Configuration to the actual job or crawler and choose encryption modes and keys that meet organizational requirements. Creating the configuration resource alone does not apply it to every job.
CloudWatch Logs and new S3 objects provide default encryption at rest, so a missing Glue KMS setting does not establish plaintext storage. S3 also supports SSE-S3; assess the need for a customer managed key separately.
Potential impact
Encryption modes or keys that do not meet requirements can leave organizational key-control requirements unmet for job data. Missing KMS permissions or unavailable keys can cause logging, data processing or recovery to fail. Encryption does not replace access controls for logs and results.
Remediation
- For CloudWatch logs that require KMS, specify
cloudwatch_encryption_mode = "SSE-KMS"and an appropriatekms_key_arn. - If job bookmarks require additional client-side encryption, configure
job_bookmarks_encryption_mode = "CSE-KMS"and a key. ChooseSSE-KMSorSSE-S3for S3 according to requirements. - Check key permissions for the jobs, crawlers and services using the configuration. After a real run, verify encryption and read access for logs, bookmarks and result objects.
Examples
Prepare the referenced symmetric KMS key and permissions separately. These configurations must also be attached to the job or crawler that uses them.
Log key not specified
resource "aws_glue_security_configuration" "glue_security" {
name = "example"
encryption_configuration {
cloudwatch_encryption {
cloudwatch_encryption_mode = "SSE-KMS"
}
job_bookmarks_encryption {
job_bookmarks_encryption_mode = "CSE-KMS"
kms_key_arn = data.aws_kms_key.example.arn
}
s3_encryption {
kms_key_arn = data.aws_kms_key.example.arn
s3_encryption_mode = "SSE-KMS"
}
}
}
This selects KMS encryption for CloudWatch logs without specifying the key to use. This setting alone does not show that logs are stored in plaintext.
Log key specified
resource "aws_glue_security_configuration" "glue_security" {
name = "example"
encryption_configuration {
cloudwatch_encryption {
cloudwatch_encryption_mode = "SSE-KMS"
kms_key_arn = data.aws_kms_key.example.arn
}
job_bookmarks_encryption {
job_bookmarks_encryption_mode = "CSE-KMS"
kms_key_arn = data.aws_kms_key.example.arn
}
s3_encryption {
kms_key_arn = data.aws_kms_key.example.arn
s3_encryption_mode = "SSE-KMS"
}
}
}
This specifies KMS keys for logs, job bookmarks and S3 results. Verify key policies and that the configuration is actually applied.