Skip to content

(aws-synthetics): support customer-managed KMS key for canary environment variable encryption #38797

Description

@shukrash

Describe the feature

AWS::Synthetics::Canary exposes a top-level KmsKeyArn property that encrypts the
canary's Lambda function environment variables at rest with a customer-managed KMS key.
The Canary L2 construct currently provides no way to set it — users must drop down to
the L1 CfnCanary or use escape hatches.

This is distinct from the existing artifactS3KmsKey prop, which encrypts canary
artifacts in S3 (ArtifactConfig.S3Encryption.KmsKeyArn), not the environment variables.

Use Case

Teams with compliance requirements to use customer-managed keys (CMKs) for all
data-at-rest need to encrypt canary environment variables (which can hold configuration
and sensitive values) with their own KMS key rather than the default AWS-managed key.

Proposed Solution

Add an optional environmentVariablesEncryptionKey?: kms.IKey prop to CanaryProps,
wire it to CfnCanary.kmsKeyArn, and grant the canary execution role kms:Decrypt on
the key so the underlying Lambda can read its environment variables.

Other Information

Follow-up: AWS::Synthetics::Canary also has a per-replica Replicas[].KmsKeyArn for
the multi-location canary feature. That will be addressed in a separate PR once the L2
models Replicas.

A PR implementing the top-level property is already open.

Acknowledgements

  • I may be able to implement this feature request
  • This feature might incur a breaking change

AWS CDK Library version (aws-cdk-lib)

2.268.0

AWS CDK CLI version

2.1140.0

Environment details (OS name and version, etc.)

OS: Amazon Linux 2023 (2023.7.20250623) Kernel: Linux 6.1.182-227.379.amzn2023.x86_64 Architecture: x86_64 Node.js: v24.18.0

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    @aws-cdk/aws-syntheticsRelated to Amazon CloudWatch Syntheticsclosing-soonThis issue will automatically close in 4 days unless further comments are made.effort/mediumMedium work item – several days of effortfeature-requestA feature should be added or improved.mixinsp2response-requestedWaiting on additional info and feedback. Will move to "closing-soon" in 7 days.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions