Description
SageMaker notebooks can store analysis code, experimental data and results. When kms_key_id is omitted, SageMaker encrypts both the operating-system and ML data volumes with a system-managed KMS key. Omission does not mean plaintext storage.
Use a customer managed key for the ML data volume when separate key policies and lifecycle controls are required. This setting does not replace notebook access controls or encryption of S3 files.
Potential impact
The default key might not meet an organization's key management requirements. Removing key permissions or disabling the key can interrupt data access and notebook operation.
Remediation
- If a separate key is required, specify an enabled KMS key in the same Region through
kms_key_idand grant the required usage permissions. - Keep files requiring that key's protection on the ML data volume at
/home/ec2-user/SageMaker. Review S3 and IAM permissions separately. - Changing the key in Terraform replaces the instance. Back up required files, move them to the new notebook and verify operation.
Examples
These excerpts show notebook creation settings. Define the required execution role in the full configuration and replace the example ARN with an available key's actual ARN.
Default encryption key
resource "aws_sagemaker_notebook_instance" "ml_notebook" {
name = "my-notebook-instance"
role_arn = aws_iam_role.sagemaker_role.arn
instance_type = "ml.t2.medium"
}
This uses a system-managed key. Check whether your organization requires separate key controls.
Customer managed key
resource "aws_sagemaker_notebook_instance" "ml_notebook" {
name = "my-notebook-instance"
role_arn = aws_iam_role.sagemaker_role.arn
instance_type = "ml.t2.medium"
kms_key_id = "arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab"
}
This selects the ML data volume's key. It does not automatically migrate existing files or restrict notebook users' access.