RDS encryption - Switch from KMS AWS Managed Key to Customer Managed Key

0

Hello, I'm working with a customer who has encrypted their RDS instances with KMS AWS Managed Key. Now, due to the need to use AWS Backup with cross-account backup they need to switch from AWS Managed key to Customer Managed key. What is the AWS recommended procedure to perform the switch also considering that the customer has a retention policy for production backup of 31 days and of course they don't want to loose existing backup ? Thanks in advance, Enrico

1개 답변
1

As described in the following AWS blog, Customer Managed key is used to encrypt the backup vault.
Cross-accounting can be set up by sharing that Customer Managed key with the destination account.
https://aws.amazon.com/jp/blogs/storage/protecting-encrypted-amazon-rds-instances-with-cross-account-and-cross-region-backups/

profile picture
전문가
답변함 일 년 전
  • The issue is that the customer has 31 days of RDS snapshots encrypted with AWS Managed Key and need to convert them to snapshots encrypted with Customer Managed Key before to copy them to the destination account in order to avoid losing any previous backup (retention policy for this customer is 31 days). The customer is asking for the recommended procedure to make conversion and copy to the destination account.

  • It would be a good idea to include a setting to copy from the existing backup vault to a backup vault encrypted with a customer-managed key, and from there to other accounts.

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠