-
Notifications
You must be signed in to change notification settings - Fork 4.6k
(aws-synthetics): support customer-managed KMS key for canary environment variable encryption #38797
Copy link
Copy link
Closed
Labels
@aws-cdk/aws-syntheticsRelated to Amazon CloudWatch SyntheticsRelated to Amazon CloudWatch Syntheticsclosing-soonThis issue will automatically close in 4 days unless further comments are made.This issue will automatically close in 4 days unless further comments are made.effort/mediumMedium work item – several days of effortMedium work item – several days of effortfeature-requestA feature should be added or improved.A feature should be added or improved.mixinsp2response-requestedWaiting on additional info and feedback. Will move to "closing-soon" in 7 days.Waiting on additional info and feedback. Will move to "closing-soon" in 7 days.
Description
Activity
Metadata
Metadata
Assignees
Labels
@aws-cdk/aws-syntheticsRelated to Amazon CloudWatch SyntheticsRelated to Amazon CloudWatch Syntheticsclosing-soonThis issue will automatically close in 4 days unless further comments are made.This issue will automatically close in 4 days unless further comments are made.effort/mediumMedium work item – several days of effortMedium work item – several days of effortfeature-requestA feature should be added or improved.A feature should be added or improved.mixinsp2response-requestedWaiting on additional info and feedback. Will move to "closing-soon" in 7 days.Waiting on additional info and feedback. Will move to "closing-soon" in 7 days.
Describe the feature
AWS::Synthetics::Canaryexposes a top-levelKmsKeyArnproperty that encrypts thecanary's Lambda function environment variables at rest with a customer-managed KMS key.
The
CanaryL2 construct currently provides no way to set it — users must drop down tothe L1
CfnCanaryor use escape hatches.This is distinct from the existing
artifactS3KmsKeyprop, which encrypts canaryartifacts in S3 (
ArtifactConfig.S3Encryption.KmsKeyArn), not the environment variables.Use Case
Teams with compliance requirements to use customer-managed keys (CMKs) for all
data-at-rest need to encrypt canary environment variables (which can hold configuration
and sensitive values) with their own KMS key rather than the default AWS-managed key.
Proposed Solution
Add an optional
environmentVariablesEncryptionKey?: kms.IKeyprop toCanaryProps,wire it to
CfnCanary.kmsKeyArn, and grant the canary execution rolekms:Decryptonthe key so the underlying Lambda can read its environment variables.
Other Information
Follow-up:
AWS::Synthetics::Canaryalso has a per-replicaReplicas[].KmsKeyArnforthe multi-location canary feature. That will be addressed in a separate PR once the L2
models
Replicas.A PR implementing the top-level property is already open.
Acknowledgements
AWS CDK Library version (aws-cdk-lib)
2.268.0
AWS CDK CLI version
2.1140.0
Environment details (OS name and version, etc.)
OS: Amazon Linux 2023 (2023.7.20250623) Kernel: Linux 6.1.182-227.379.amzn2023.x86_64 Architecture: x86_64 Node.js: v24.18.0