Secrets Manager secret encrypted with an AWS managed key

Check whether the AWS managed Secrets Manager key meets your key-management requirements.

Description

The AWS managed key aws/secretsmanager also encrypts secret values using KMS. Its use alone does not mean encryption is weak or the secret is public.

However, you cannot edit an AWS managed key's policy. A customer-managed KMS key may be required where the organization must directly control key policies and lifecycle.

Potential impact

The configuration may not meet organizational key-control requirements. A customer-managed key does not resolve excessive secret-read permissions, and incorrect key-permission changes can prevent applications from retrieving secrets.

Remediation

  • Choose a customer-managed symmetric encryption KMS key when required and set kms_key_id to its ARN or alias.
  • Review the secret policy, IAM permissions and key policy together. Grant read and key-use permissions only to the necessary principals.
  • After changing keys, verify that the required secret versions can be read. Do not remove access to previous keys while existing versions still need them.

Examples

These excerpts show only key selection for the secret resource. Manage the secret value separately.

AWS managed key

hcl
resource "aws_secretsmanager_secret" "example" {
  name       = "test-cloudrail-1"
  kms_key_id = "alias/aws/secretsmanager"
}

This encrypts secret values using a key policy managed by AWS.

Customer-managed key

hcl
resource "aws_secretsmanager_secret" "example" {
  name       = "test-cloudrail-1"
  kms_key_id = "alias/MyAlias"
}

Replace alias/MyAlias with an actual customer-managed key alias in the same Region and verify the caller's key permissions. Changing the key type alone does not restrict access to the secret.

References