Description
Event streams can contain user activity, application logs and internal messages. Kinesis server-side encryption protects records stored in a stream using KMS. Check that the actual encryption state and chosen key meet data-protection requirements.
Encryption applies to records arriving after it is enabled. It does not retroactively encrypt earlier unencrypted records. Stream access controls and protection in transit remain separate requirements.
Potential impact
With server-side encryption disabled, newly stored sensitive records may not meet organizational encryption-at-rest requirements. Incorrect key or permission settings can interrupt data writes or reads.
Remediation
- Explicitly set
encryption_type = "KMS"and a validkms_key_id. Choose an AWS managed key or a customer managed key required by the organization. - Limit KMS permissions for data producers and consumers to what they need.
- After the change completes, verify the actual stream state, encryption of new records, and successful writes and reads. Review retention and handling of earlier records too.
Examples
Before
resource "aws_kinesis_stream" "event_stream" {
name = "terraform-kinesis-test"
shard_count = 1
retention_period = 48
encryption_type = "NONE"
}
This configures the stream without server-side encryption.
After
resource "aws_kinesis_stream" "event_stream" {
name = "terraform-kinesis-test"
shard_count = 1
retention_period = 48
encryption_type = "KMS"
kms_key_id = "alias/aws/kinesis"
}
This requests encryption with alias/aws/kinesis, the alias for the AWS managed Kinesis key. Verify protection of new records after activation; earlier records are not retroactively encrypted.