WorkSpace without volume encryption

Encrypt both WorkSpaces volumes at creation and plan migration of existing user data.

Description

The root and user volumes of a WorkSpace store operating-system settings, documents and business data. Encrypting only one volume leaves data on the other without the same protection. Volume encryption protects the volume and its snapshots, but does not prevent compromise of user accounts or devices.

Potential impact

Unauthorized access to an unencrypted volume or snapshot increases the risk of exposing business files and settings. The configuration may also fail organizational encryption requirements.

Remediation

  • Set both root_volume_encryption_enabled = true and user_volume_encryption_enabled = true for new WorkSpaces.
  • Specify an appropriate AWS managed or customer managed KMS key in volume_encryption_key, keeping the key enabled and required permissions available.
  • Volume encryption cannot be enabled on an existing WorkSpace after creation. Review Terraform's replacement plan, preserve the data and move it to a new encrypted WorkSpace. Manage user authentication and access separately.

Examples

These excerpts show creation settings. Supply a real directory, bundle and user, with compatible volume sizes, in the complete configuration.

Before

hcl
resource "aws_workspaces_workspace" "user_desktop" {
  directory_id = aws_workspaces_directory.example.id
  bundle_id    = data.aws_workspaces_bundle.value_windows_10.id
  user_name    = "john.doe"

  root_volume_encryption_enabled = true
  volume_encryption_key          = "alias/aws/workspaces"

  workspace_properties {
    user_volume_size_gib = 10
    root_volume_size_gib = 80
  }
}

Only root-volume encryption is requested; user-volume encryption is not configured.

After

hcl
resource "aws_workspaces_workspace" "user_desktop" {
  directory_id = aws_workspaces_directory.example.id
  bundle_id    = data.aws_workspaces_bundle.value_windows_10.id
  user_name    = "john.doe"

  root_volume_encryption_enabled = true
  user_volume_encryption_enabled = true
  volume_encryption_key          = "alias/aws/workspaces"

  workspace_properties {
    user_volume_size_gib = 10
    root_volume_size_gib = 80
  }
}

This requests encryption for both volumes of a new WorkSpace. It does not automatically migrate existing user files.

References