Description
Invalid server_side_encryption settings on Amazon Data Firehose can prevent the requested encryption configuration from being applied or delay delivery through key-access failures. Direct PUT sources use AWS_OWNED_CMK or CUSTOMER_MANAGED_CMK; selecting a customer managed key requires a valid key_arn.
Firehose also encrypts data held in interim storage during processing. With Kinesis Data Streams as the source, review encryption on the source stream. Manage destination encryption and access permissions separately.
Potential impact
- Invalid key settings can disrupt deployment, ingestion or delivery.
- The configuration may not meet customer managed key and audit requirements.
Remediation
For Direct PUT streams, set server_side_encryption.enabled to true and choose an appropriate key_type. For CUSTOMER_MANAGED_CMK, provide an available symmetric KMS key ARN and the required permissions. Check the encryption method for the input source and test the applied state and actual data delivery.
Examples
These are encryption excerpts for a Direct PUT stream. Destination and role settings are omitted; supply an available symmetric KMS key ARN in var.firehose_kms_key_arn.
Before
resource "aws_kinesis_firehose_delivery_stream" "firehose_stream" {
name = "${aws_s3_bucket.logs.bucket}-firehose"
destination = "extended_s3"
server_side_encryption {
enabled = true
key_type = "AWS_OWN"
}
}
AWS_OWN is not a valid key_type and must be corrected.
After
resource "aws_kinesis_firehose_delivery_stream" "firehose_stream" {
name = "${aws_s3_bucket.logs.bucket}-firehose"
destination = "extended_s3"
server_side_encryption {
enabled = true
key_type = "CUSTOMER_MANAGED_CMK"
key_arn = var.firehose_kms_key_arn
}
}
This uses CUSTOMER_MANAGED_CMK and a key ARN input. Check key availability, permissions and the stream’s encryption status.