Description
SageMaker endpoint storage volumes can hold data and temporary files used by the model. The kms_key_arn setting in aws_sagemaker_endpoint_configuration selects the encryption key for this storage. SageMaker encrypts storage volumes by default even when the key is omitted, so omission does not mean plaintext storage.
Use a customer managed KMS key for supported storage volumes when separate key policies and lifecycle controls are required. Local storage on some Nitro instances is encrypted in hardware and is outside the scope of this KMS setting.
Potential impact
Default encryption might not meet an organization's key management requirements. Removing required key permissions or disabling the key can also affect endpoint deployment and operation.
Remediation
- Check the instance's storage type and key requirements. If a separate key is needed, set
kms_key_arnto its actual ARN. - Grant the permissions SageMaker needs to use the key. Apply the new endpoint configuration and verify that inference requests succeed.
- Review encryption and access permissions for S3 model files, data capture and logs separately. Volume encryption does not replace transport protection or authorization to invoke the endpoint.
Examples
These excerpts show endpoint configuration. Define the model and required permissions in the complete configuration.
Key omitted
resource "aws_sagemaker_endpoint_configuration" "ml_endpoint_config" {
name = "my-endpoint-config"
production_variants {
variant_name = "variant-1"
model_name = aws_sagemaker_model.model.name
initial_instance_count = 1
instance_type = "ml.t2.medium"
}
}
No separate KMS key is specified. Compare the default storage encryption with your key management requirements.
KMS key specified
resource "aws_sagemaker_endpoint_configuration" "ml_endpoint_config" {
name = "my-endpoint-config"
production_variants {
variant_name = "variant-1"
model_name = aws_sagemaker_model.model.name
initial_instance_count = 1
instance_type = "ml.t2.medium"
}
kms_key_arn = aws_kms_key.sagemaker.arn
}
This selects a key for supported storage volumes. It does not change the encryption key for all data stored in S3.