Description
With alias/aws/sns, SNS encrypts stored message bodies using an AWS managed KMS key. Using this key does not itself mean plaintext storage or weaker encryption.
However, AWS manages the key policy and you cannot edit it. Use a customer-managed KMS key where the organization must directly control key policy and lifecycle.
Potential impact
Using the default key on a message path requiring customer-managed keys may fail organizational requirements. Incorrect key restrictions can interrupt publishing or delivery; topic policies and subscription destinations need review regardless of key type.
Remediation
- When a customer-managed key is required, set
kms_master_key_idto an actual symmetric encryption KMS key ARN or alias. - Review topic and key policies together, granting publishers and integrated services the key permissions they need.
- Verify publishing and delivery after the change, and retain key access needed to process existing messages. Manage transit encryption and message-metadata protection separately.
Examples
These separate topics compare key selection. Keep the topic name unchanged when changing only the key of an existing topic.
AWS managed key
resource "aws_sns_topic" "example" {
name = "user-updates-topic"
kms_master_key_id = "alias/aws/sns"
}
This encrypts stored message bodies using an AWS managed key.
Customer-managed key
resource "aws_sns_topic" "example" {
name = "sns_ecnrypted"
kms_master_key_id = "alias/MyAlias"
}
Replace alias/MyAlias with the alias of the actual customer-managed key. Prepare the key policy and necessary use permissions as well.