Review additional KMS encryption for SSM sessions

Distinguish Session Manager’s default TLS protection from requirements for additional KMS encryption.

Description

Session Manager uses TLS for session communication by default. Omitting kmsKeyId does not mean the session travels in plaintext. KMS adds another encryption layer to this default protection for supported session types.

Where operational commands and responses require an additional organization-controlled key, configure both the document actually used by sessions and the necessary key permissions.

Potential impact

The configuration may not meet operational requirements for additional KMS encryption. Incorrect key permissions can prevent sessions from starting, and additional encryption does not restrict excessive operational access by itself.

Remediation

  • When required, specify a symmetric KMS key in inputs.kmsKeyId of a supported Session document.
  • Grant the necessary key permissions to both session-starting users and managed nodes, and use a supported SSM Agent.
  • Confirm that sessions actually use this document and test a new connection. Configure session-log destinations and storage encryption separately.

Examples

These excerpts configure Standard_Stream session preferences. Log-encryption flags alone do not specify log destinations; prepare any required logging configuration separately.

Default TLS protection

hcl
resource "aws_ssm_document" "example" {
  name          = "test_document"
  document_type = "Session"

  content = <<DOC
  {
    "schemaVersion": "1.0",
    "description": "Session preferences",
    "sessionType": "Standard_Stream",
    "inputs": {
      "s3EncryptionEnabled": true,
      "cloudWatchEncryptionEnabled": true,
      "cloudWatchStreamingEnabled": true,
      "runAsEnabled": false
    }
  }
DOC
}

No additional KMS key is specified; default TLS protection remains in place.

Additional KMS encryption

hcl
resource "aws_ssm_document" "example" {
  name          = "test_document"
  document_type = "Session"

  content = <<DOC
  {
    "schemaVersion": "1.0",
    "description": "Session preferences",
    "sessionType": "Standard_Stream",
    "inputs": {
      "s3EncryptionEnabled": true,
      "cloudWatchEncryptionEnabled": true,
      "cloudWatchStreamingEnabled": true,
      "runAsEnabled": false,
      "kmsKeyId": "${var.kms_key_id}"
    }
  }
DOC
}

Supply the actual key through var.kms_key_id and prepare permissions for sessions using this document. Creating a custom document alone does not automatically apply it to every session.

References