Description
Session Manager uses TLS for session communication by default. Omitting kmsKeyId does not mean the session travels in plaintext. KMS adds another encryption layer to this default protection for supported session types.
Where operational commands and responses require an additional organization-controlled key, configure both the document actually used by sessions and the necessary key permissions.
Potential impact
The configuration may not meet operational requirements for additional KMS encryption. Incorrect key permissions can prevent sessions from starting, and additional encryption does not restrict excessive operational access by itself.
Remediation
- When required, specify a symmetric KMS key in
inputs.kmsKeyIdof a supported Session document. - Grant the necessary key permissions to both session-starting users and managed nodes, and use a supported SSM Agent.
- Confirm that sessions actually use this document and test a new connection. Configure session-log destinations and storage encryption separately.
Examples
These excerpts configure Standard_Stream session preferences. Log-encryption flags alone do not specify log destinations; prepare any required logging configuration separately.
Default TLS protection
resource "aws_ssm_document" "example" {
name = "test_document"
document_type = "Session"
content = <<DOC
{
"schemaVersion": "1.0",
"description": "Session preferences",
"sessionType": "Standard_Stream",
"inputs": {
"s3EncryptionEnabled": true,
"cloudWatchEncryptionEnabled": true,
"cloudWatchStreamingEnabled": true,
"runAsEnabled": false
}
}
DOC
}
No additional KMS key is specified; default TLS protection remains in place.
Additional KMS encryption
resource "aws_ssm_document" "example" {
name = "test_document"
document_type = "Session"
content = <<DOC
{
"schemaVersion": "1.0",
"description": "Session preferences",
"sessionType": "Standard_Stream",
"inputs": {
"s3EncryptionEnabled": true,
"cloudWatchEncryptionEnabled": true,
"cloudWatchStreamingEnabled": true,
"runAsEnabled": false,
"kmsKeyId": "${var.kms_key_id}"
}
}
DOC
}
Supply the actual key through var.kms_key_id and prepare permissions for sessions using this document. Creating a custom document alone does not automatically apply it to every session.