Review RDS cluster snapshot encryption

Check the actual encryption of RDS cluster snapshots and their source clusters together.

Description

A cluster snapshot is both a recovery backup and a copy of sensitive data. Snapshot encryption follows the source cluster’s actual encryption state, so check the source and snapshot together.

Omitting storage_encrypted does not necessarily leave the source unencrypted. New Aurora clusters currently use default encryption, while restored or cloned clusters can differ according to their source and creation method.

Potential impact

Unauthorized acquisition of an actually unencrypted snapshot can expose recovery data. Backup-encryption requirements may also be unmet. Manage snapshot sharing and KMS key access separately.

Remediation

  • Check the actual source cluster and snapshot encryption, and explicitly select required encryption and keys for new clusters.
  • For an existing unencrypted snapshot, create an encrypted copy using the supported copy operation and verify restoration. Changing the source cluster’s setting alone does not encrypt existing snapshots.
  • If cluster migration is needed, review Terraform replacement, data consistency and application cutover, preserving the original and required keys.

Examples

These excerpts show the relationship between a snapshot and its source cluster. Configure required engine, authentication and networking settings separately. Because skip_final_snapshot = true omits a final snapshot when deleting the cluster, a separate backup-retention policy is needed.

Encryption setting omitted

hcl
resource "aws_db_cluster_snapshot" "db_snapshot" {
  db_cluster_identifier          = aws_rds_cluster.example2.id
  db_cluster_snapshot_identifier = "resourcetestsnapshot1234"
}

resource "aws_rds_cluster" "example2" {
  cluster_identifier  = "example"
  skip_final_snapshot = true
}

The source’s encryption is not explicit. This excerpt alone does not establish that the actual snapshot is unencrypted.

Encryption explicitly enabled

hcl
resource "aws_db_cluster_snapshot" "db_snapshot" {
  db_cluster_identifier          = aws_rds_cluster.example.id
  db_cluster_snapshot_identifier = "resourcetestsnapshot1234"
}

resource "aws_rds_cluster" "example" {
  cluster_identifier  = "example"
  skip_final_snapshot = true
  storage_encrypted   = true
}

This explicitly requests encryption for the source cluster. Neither excerpt replaces a data-migration procedure for existing clusters or snapshots.

References