Description
Azure PostgreSQL encrypts stored data and backups by default. A false infrastructure_encryption_enabled value on legacy Single Server does not mean plaintext storage. AzureRM 3.117.1 documentation states that Microsoft does not support this option and recommends against setting it to true.
Potential impact
- An unsupported encryption option can cause performance degradation and operational errors.
- Assuming default encryption satisfies separate customer-managed key or additional encryption-layer requirements can leave required controls unmet.
Remediation
Review storage encryption and key-management requirements on supported Flexible Server. If customer-managed keys are required, plan the supported configuration and key access and recovery procedures; do not equate them with a second encryption layer. Review backups, TLS and network access, and plan migration from retired Single Server separately.
Examples
The before example is a historical retired Single Server configuration. The after excerpt uses Flexible Server in AzureRM 5.6.0 without the unsupported infrastructure_encryption_enabled option. Configure authentication, capacity and actual private connectivity separately.
Before
resource "azurerm_postgresql_server" "example" {
name = "example-psqlserver"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
public_network_access_enabled = false
ssl_enforcement_enabled = true
ssl_minimal_tls_version_enforced = "TLS1_2"
infrastructure_encryption_enabled = false
}
After
resource "azurerm_postgresql_flexible_server" "example" {
name = "example-psqlserver"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
public_network_access_enabled = false
}
Flexible Server provides default encryption at rest. This example does not enable an additional encryption layer, and changing the resource type alone does not migrate existing data.