AWS KMS

· 1 min read · AWS

AWS Key Management Service (KMS) is a managed service to create and control cryptographic keys. Most AWS services integrate with it to encrypt data at rest: S3, EBS, RDS, Secrets Manager, DynamoDB, CloudWatch logs and more. The keys are protected in FIPS 140 validated hardware security modules and never leave KMS unencrypted.

Key concepts #

  • KMS key (formerly customer master key): the main resource. Symmetric keys (AES-256) are the most common; asymmetric keys are also available for signing and encryption.
  • AWS managed keys are created and managed by AWS for each service (for example aws/rds), at no monthly cost. Customer managed keys are created by you and give full control of policy, rotation and deletion.
  • Key policy and IAM policies control who can use and administer the key. Every key has a key policy.
  • Alias: a friendly name (alias/ditwl-kms-rds-001-key) that points to a key and can be changed without changing the applications.
  • Automatic rotation of customer managed keys changes the key material every year (the period is configurable) and keeps decrypting data encrypted with older material.
  • Envelope encryption: KMS encrypts small data keys, and the data keys encrypt the large data. It is how S3 or EBS use KMS.
  • A key is bound to a Region. Multi-Region keys can be replicated.
  • Deletion has a mandatory waiting period (7 to 30 days) because deleting a key makes the data encrypted with it unrecoverable.

Pricing #

Customer managed keys have a monthly charge per key plus a charge per request. AWS managed keys have no monthly charge. See the KMS pricing.

With Terraform #

The resources are aws_kms_key, aws_kms_alias, aws_kms_key_policy and aws_kms_grant.

resource "aws_kms_key" "rds" {
  description         = "RDS key"
  enable_key_rotation = true
}

resource "aws_kms_alias" "rds" {
  name          = "alias/rds-key"
  target_key_id = aws_kms_key.rds.key_id
}

See tutorials:

More tutorials that use KMS

#AWS #AWS KMS #Security