AWS Neptune cluster without encryption at rest

Encrypt Neptune storage and backups, and prepare migration and recovery for existing data.

Description

Graph databases can hold relationship data, user connections and business data that need encryption at rest. Neptune encryption protects cluster storage, logs, backups and snapshots.

An actually unencrypted cluster lacks this storage protection. IAM database authentication and network or transport protection require separate management.

Potential impact

Unauthorized acquisition of unencrypted storage or backups can expose sensitive graph data. Database encryption requirements may also be unmet. If a KMS key in use becomes unavailable, data access and recovery can be affected.

Remediation

  • Explicitly set storage_encrypted = true for new clusters and verify organizational KMS key and permission requirements.
  • Changing a setting alone cannot encrypt an existing unencrypted cluster. Plan migration by restoring an unencrypted snapshot to a new encrypted cluster, specifying the KMS key during restore.
  • Verify Terraform replacement, data consistency, application connections and backup recovery, preserving the original data and required keys.

Examples

These are new-cluster configuration excerpts. Prepare required instances and networking separately.

Before

hcl
resource "aws_neptune_cluster" "neptune_cluster" {
  cluster_identifier                  = "neptune-cluster-demo"
  engine                              = "neptune"
  iam_database_authentication_enabled = true
  storage_encrypted                   = false
}

Enabling IAM authentication does not compensate for disabled encryption at rest.

After

hcl
resource "aws_neptune_cluster" "neptune_cluster" {
  cluster_identifier                  = "neptune-cluster-demo"
  engine                              = "neptune"
  iam_database_authentication_enabled = true
  storage_encrypted                   = true
}

This requests encryption at rest for a new cluster. It does not replace a migration procedure for existing data.

References