Amazon Data Firehose encryption settings need review

Match Firehose encryption settings to the input source and key-management requirements.

Description

Invalid server_side_encryption settings on Amazon Data Firehose can prevent the requested encryption configuration from being applied or delay delivery through key-access failures. Direct PUT sources use AWS_OWNED_CMK or CUSTOMER_MANAGED_CMK; selecting a customer managed key requires a valid key_arn.

Firehose also encrypts data held in interim storage during processing. With Kinesis Data Streams as the source, review encryption on the source stream. Manage destination encryption and access permissions separately.

Potential impact

  • Invalid key settings can disrupt deployment, ingestion or delivery.
  • The configuration may not meet customer managed key and audit requirements.

Remediation

For Direct PUT streams, set server_side_encryption.enabled to true and choose an appropriate key_type. For CUSTOMER_MANAGED_CMK, provide an available symmetric KMS key ARN and the required permissions. Check the encryption method for the input source and test the applied state and actual data delivery.

Examples

These are encryption excerpts for a Direct PUT stream. Destination and role settings are omitted; supply an available symmetric KMS key ARN in var.firehose_kms_key_arn.

Before

hcl
resource "aws_kinesis_firehose_delivery_stream" "firehose_stream" {
  name        = "${aws_s3_bucket.logs.bucket}-firehose"
  destination = "extended_s3"

  server_side_encryption {
    enabled  = true
    key_type = "AWS_OWN"
  }
}

AWS_OWN is not a valid key_type and must be corrected.

After

hcl
resource "aws_kinesis_firehose_delivery_stream" "firehose_stream" {
  name        = "${aws_s3_bucket.logs.bucket}-firehose"
  destination = "extended_s3"

  server_side_encryption {
    enabled  = true
    key_type = "CUSTOMER_MANAGED_CMK"
    key_arn  = var.firehose_kms_key_arn
  }
}

This uses CUSTOMER_MANAGED_CMK and a key ARN input. Check key availability, permissions and the stream’s encryption status.

References