Description
The root and user volumes of a WorkSpace store operating-system settings, documents and business data. Encrypting only one volume leaves data on the other without the same protection. Volume encryption protects the volume and its snapshots, but does not prevent compromise of user accounts or devices.
Potential impact
Unauthorized access to an unencrypted volume or snapshot increases the risk of exposing business files and settings. The configuration may also fail organizational encryption requirements.
Remediation
- Set both
root_volume_encryption_enabled = trueanduser_volume_encryption_enabled = truefor new WorkSpaces. - Specify an appropriate AWS managed or customer managed KMS key in
volume_encryption_key, keeping the key enabled and required permissions available. - Volume encryption cannot be enabled on an existing WorkSpace after creation. Review Terraform's replacement plan, preserve the data and move it to a new encrypted WorkSpace. Manage user authentication and access separately.
Examples
These excerpts show creation settings. Supply a real directory, bundle and user, with compatible volume sizes, in the complete configuration.
Before
resource "aws_workspaces_workspace" "user_desktop" {
directory_id = aws_workspaces_directory.example.id
bundle_id = data.aws_workspaces_bundle.value_windows_10.id
user_name = "john.doe"
root_volume_encryption_enabled = true
volume_encryption_key = "alias/aws/workspaces"
workspace_properties {
user_volume_size_gib = 10
root_volume_size_gib = 80
}
}
Only root-volume encryption is requested; user-volume encryption is not configured.
After
resource "aws_workspaces_workspace" "user_desktop" {
directory_id = aws_workspaces_directory.example.id
bundle_id = data.aws_workspaces_bundle.value_windows_10.id
user_name = "john.doe"
root_volume_encryption_enabled = true
user_volume_encryption_enabled = true
volume_encryption_key = "alias/aws/workspaces"
workspace_properties {
user_volume_size_gib = 10
root_volume_size_gib = 80
}
}
This requests encryption for both volumes of a new WorkSpace. It does not automatically migrate existing user files.