# AWS KMS

> AWS Key Management Service (KMS) creates and controls the cryptographic keys that encrypt data in S3, EBS, RDS, Secrets Manager and many other AWS services.

- Source: https://www.itwonderlab.com/aws-kms/
- Published: 2026-10-05
- Updated: 2026-10-05
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**AWS Key Management Service (KMS)** is a managed service to create and control cryptographic keys. Most AWS services integrate with it to encrypt data at rest: [S3](https://www.itwonderlab.com/aws-s3/), [EBS](https://www.itwonderlab.com/aws-ebs/), [RDS](https://www.itwonderlab.com/aws-rds/), [Secrets Manager](https://www.itwonderlab.com/aws-secrets-manager/), [DynamoDB](https://www.itwonderlab.com/aws-dynamodb/), [CloudWatch](https://www.itwonderlab.com/aws-cloudwatch/) logs and more. The keys are protected in FIPS 140 validated hardware security modules and never leave KMS unencrypted.

### Key concepts

- **KMS key** (formerly *customer master key*): the main resource. Symmetric keys (AES-256) are the most common; asymmetric keys are also available for signing and encryption.
- **AWS managed keys** are created and managed by AWS for each service (for example `aws/rds`), at no monthly cost. **Customer managed keys** are created by you and give full control of policy, rotation and deletion.
- **Key policy** and [IAM](https://www.itwonderlab.com/aws-iam/) policies control who can use and administer the key. Every key has a key policy.
- **Alias**: a friendly name (`alias/ditwl-kms-rds-001-key`) that points to a key and can be changed without changing the applications.
- **Automatic rotation** of customer managed keys changes the key material every year (the period is configurable) and keeps decrypting data encrypted with older material.
- **Envelope encryption**: KMS encrypts small *data keys*, and the data keys encrypt the large data. It is how S3 or EBS use KMS.
- A key is bound to a **Region**. Multi-Region keys can be replicated.
- **Deletion** has a mandatory waiting period (7 to 30 days) because deleting a key makes the data encrypted with it unrecoverable.

### Pricing

Customer managed keys have a monthly charge per key plus a charge per request. AWS managed keys have no monthly charge. See the [KMS pricing](https://aws.amazon.com/kms/pricing/).

### With Terraform

The resources are `aws_kms_key`, `aws_kms_alias`, `aws_kms_key_policy` and `aws_kms_grant`.

```hcl
resource "aws_kms_key" "rds" {
  description         = "RDS key"
  enable_key_rotation = true
}

resource "aws_kms_alias" "rds" {
  name          = "alias/rds-key"
  target_key_id = aws_kms_key.rds.key_id
}
```

See tutorials:

-   [AWS with Terraform: The Essential Guide (13/21) – AWS RDS](https://www.itwonderlab.com/aws-terraform-tutorial-aws-rds/)
-   [How to Encrypt Terraform State with OpenTofu](https://www.itwonderlab.com/terraform-state-file-encryption/)
