AWS KMS
AWS Key Management Service (KMS) is a managed service to create and control cryptographic keys. Most AWS services integrate with it to encrypt data at rest: S3, EBS, RDS, Secrets Manager, DynamoDB, CloudWatch logs and more. The keys are protected in FIPS 140 validated hardware security modules and never leave KMS unencrypted.
Key concepts #
- KMS key (formerly customer master key): the main resource. Symmetric keys (AES-256) are the most common; asymmetric keys are also available for signing and encryption.
- AWS managed keys are created and managed by AWS for each service (for example
aws/rds), at no monthly cost. Customer managed keys are created by you and give full control of policy, rotation and deletion. - Key policy and IAM policies control who can use and administer the key. Every key has a key policy.
- Alias: a friendly name (
alias/ditwl-kms-rds-001-key) that points to a key and can be changed without changing the applications. - Automatic rotation of customer managed keys changes the key material every year (the period is configurable) and keeps decrypting data encrypted with older material.
- Envelope encryption: KMS encrypts small data keys, and the data keys encrypt the large data. It is how S3 or EBS use KMS.
- A key is bound to a Region. Multi-Region keys can be replicated.
- Deletion has a mandatory waiting period (7 to 30 days) because deleting a key makes the data encrypted with it unrecoverable.
Pricing #
Customer managed keys have a monthly charge per key plus a charge per request. AWS managed keys have no monthly charge. See the KMS pricing.
With Terraform #
The resources are aws_kms_key, aws_kms_alias, aws_kms_key_policy and aws_kms_grant.
resource "aws_kms_key" "rds" {
description = "RDS key"
enable_key_rotation = true
}
resource "aws_kms_alias" "rds" {
name = "alias/rds-key"
target_key_id = aws_kms_key.rds.key_id
}
See tutorials: