Review the KMS key deletion waiting period

Assess deletion impacts and allow enough time to cancel an unintended deletion.

Description

KMS key deletion requires a waiting period of 7–30 days. Omitting Terraform’s deletion_window_in_days uses the default of 30 days; omission does not mean immediate deletion. Choose a period that gives operators enough time to detect and cancel an unintended request.

Potential impact

  • A key pending deletion cannot perform cryptographic operations, which can disrupt dependent services.
  • Actual deletion is irreversible and can make ciphertext requiring that key impossible to decrypt.

Remediation

Identify key consumers and recovery options, and control deletion approval. If setting deletion_window_in_days explicitly, choose 7–30 days with enough time to respond. Cancel an unintended deletion before the period ends and restore the required key’s operational state.

Examples

These examples compare the default waiting period with an explicit value. Review dependent-service impacts before scheduling deletion.

Before

hcl
resource "aws_kms_key" "example" {
  description         = "KMS key 1"
  is_enabled          = true
  enable_key_rotation = true
}

After

hcl
resource "aws_kms_key" "example" {
  description             = "KMS key 1"
  is_enabled              = true
  enable_key_rotation     = true
  deletion_window_in_days = 10
}

The first uses the 30-day default; the second specifies 10 days. Ten days illustrates a shorter wait, not a configuration inherently safer than the default.

References