Description
Cluster databases such as Aurora store core application data, so their stored data and backups need encryption. An actually unencrypted cluster lacks this protective layer.
However, omitting storage_encrypted does not by itself establish that a cluster is unencrypted. New Aurora clusters currently use default encryption; verify the actual state of clusters created earlier, restored or cloned. Encryption does not replace database permissions or network controls.
Potential impact
Unauthorized acquisition of unencrypted storage or backups can expose customer and service data. Organizational encryption requirements may also be unmet. If a key in use becomes unavailable, data access and recovery can fail.
Remediation
- Check actual cluster and backup encryption, and explicitly configure the required
storage_encrypted = truesetting and KMS key. - An existing unencrypted cluster cannot be encrypted by changing a setting alone. Plan migration to a new cluster using supported operations such as encrypted snapshot copy and restore.
- Verify Terraform replacement, data consistency, application cutover and recovery, preserving the original and required keys.
Examples
These excerpts compare encryption settings. Configure required instances and networking separately. Securely supply a password that meets requirements and restrict access to Terraform state.
Encryption setting omitted
resource "aws_rds_cluster" "rds_cluster" {
cluster_identifier = "aurora-cluster-demo"
engine = "aurora-mysql"
master_username = "foo"
master_password = var.db_password
}
Encryption is not explicit. Given current default encryption for new Aurora clusters, this excerpt alone does not mean plaintext storage.
Encryption explicitly enabled
resource "aws_rds_cluster" "rds_cluster" {
cluster_identifier = "cloudrail-test-non-encrypted"
engine = "aurora-mysql"
master_username = "administrator"
master_password = var.db_password
storage_encrypted = true
}
This explicitly configures storage encryption. It is not a complete procedure for safely migrating existing data or clusters.