Review Azure PostgreSQL encryption at rest

Distinguish default storage encryption from additional key requirements and use supported PostgreSQL settings.

Description

Azure PostgreSQL encrypts stored data and backups by default. A false infrastructure_encryption_enabled value on legacy Single Server does not mean plaintext storage. AzureRM 3.117.1 documentation states that Microsoft does not support this option and recommends against setting it to true.

Potential impact

  • An unsupported encryption option can cause performance degradation and operational errors.
  • Assuming default encryption satisfies separate customer-managed key or additional encryption-layer requirements can leave required controls unmet.

Remediation

Review storage encryption and key-management requirements on supported Flexible Server. If customer-managed keys are required, plan the supported configuration and key access and recovery procedures; do not equate them with a second encryption layer. Review backups, TLS and network access, and plan migration from retired Single Server separately.

Examples

The before example is a historical retired Single Server configuration. The after excerpt uses Flexible Server in AzureRM 5.6.0 without the unsupported infrastructure_encryption_enabled option. Configure authentication, capacity and actual private connectivity separately.

Before

hcl
resource "azurerm_postgresql_server" "example" {
  name                = "example-psqlserver"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  public_network_access_enabled     = false
  ssl_enforcement_enabled           = true
  ssl_minimal_tls_version_enforced  = "TLS1_2"
  infrastructure_encryption_enabled = false
}

After

hcl
resource "azurerm_postgresql_flexible_server" "example" {
  name                = "example-psqlserver"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  public_network_access_enabled = false
}

Flexible Server provides default encryption at rest. This example does not enable an additional encryption layer, and changing the resource type alone does not migrate existing data.

References