Review RDS cluster storage encryption

Check actual RDS cluster encryption and defaults, and plan migration of existing data.

Description

Cluster databases such as Aurora store core application data, so their stored data and backups need encryption. An actually unencrypted cluster lacks this protective layer.

However, omitting storage_encrypted does not by itself establish that a cluster is unencrypted. New Aurora clusters currently use default encryption; verify the actual state of clusters created earlier, restored or cloned. Encryption does not replace database permissions or network controls.

Potential impact

Unauthorized acquisition of unencrypted storage or backups can expose customer and service data. Organizational encryption requirements may also be unmet. If a key in use becomes unavailable, data access and recovery can fail.

Remediation

  • Check actual cluster and backup encryption, and explicitly configure the required storage_encrypted = true setting and KMS key.
  • An existing unencrypted cluster cannot be encrypted by changing a setting alone. Plan migration to a new cluster using supported operations such as encrypted snapshot copy and restore.
  • Verify Terraform replacement, data consistency, application cutover and recovery, preserving the original and required keys.

Examples

These excerpts compare encryption settings. Configure required instances and networking separately. Securely supply a password that meets requirements and restrict access to Terraform state.

Encryption setting omitted

hcl
resource "aws_rds_cluster" "rds_cluster" {
  cluster_identifier = "aurora-cluster-demo"
  engine             = "aurora-mysql"
  master_username    = "foo"
  master_password    = var.db_password
}

Encryption is not explicit. Given current default encryption for new Aurora clusters, this excerpt alone does not mean plaintext storage.

Encryption explicitly enabled

hcl
resource "aws_rds_cluster" "rds_cluster" {
  cluster_identifier = "cloudrail-test-non-encrypted"
  engine             = "aurora-mysql"
  master_username    = "administrator"
  master_password    = var.db_password
  storage_encrypted  = true
}

This explicitly configures storage encryption. It is not a complete procedure for safely migrating existing data or clusters.

References