Description
Secrets Manager encrypts secret values using KMS. When a new secret omits kms_key_id, it uses the AWS managed key aws/secretsmanager; omission does not mean plaintext storage.
Where direct control over key policies and lifecycle is required, explicitly selecting a customer-managed key helps apply organizational standards consistently. Choose the required level of key control based on the secret's purpose and organizational policy.
Potential impact
Default-key use may not meet a policy requiring customer-managed keys. Independently of key type, excessive secret-read permissions can expose secret values.
Remediation
- Set
kms_key_idfor secrets requiring a customer-managed key, using a symmetric encryption KMS key ARN or alias. - Review key policies and secret-read permissions together, and reflect the organization's key-selection requirements in templates.
- After changing an existing secret's key, verify access to required versions and retain access for versions that depend on previous keys.
Examples
Use the default key
resource "aws_secretsmanager_secret" "example" {
name = "example"
}
The new secret uses an AWS managed key. This resource declaration does not set the secret value itself.
Specify a key
resource "aws_secretsmanager_secret" "example" {
name = "example"
kms_key_id = "arn:aws:kms:us-west-2:111122223333:key/1234abcd-12ab-34cd-56ef-1234567890ab"
}
Replace the example ARN with an actual customer-managed key ARN and prepare its permissions. Explicit key selection does not replace access restrictions on the secret.