Description
KMS key deletion requires a waiting period of 7–30 days. Omitting Terraform’s deletion_window_in_days uses the default of 30 days; omission does not mean immediate deletion. Choose a period that gives operators enough time to detect and cancel an unintended request.
Potential impact
- A key pending deletion cannot perform cryptographic operations, which can disrupt dependent services.
- Actual deletion is irreversible and can make ciphertext requiring that key impossible to decrypt.
Remediation
Identify key consumers and recovery options, and control deletion approval. If setting deletion_window_in_days explicitly, choose 7–30 days with enough time to respond. Cancel an unintended deletion before the period ends and restore the required key’s operational state.
Examples
These examples compare the default waiting period with an explicit value. Review dependent-service impacts before scheduling deletion.
Before
resource "aws_kms_key" "example" {
description = "KMS key 1"
is_enabled = true
enable_key_rotation = true
}
After
resource "aws_kms_key" "example" {
description = "KMS key 1"
is_enabled = true
enable_key_rotation = true
deletion_window_in_days = 10
}
The first uses the 30-day default; the second specifies 10 days. Ten days illustrates a shorter wait, not a configuration inherently safer than the default.