~ 4 min read

Migrating an unencrypted RDS database to an encrypted one

Encrypting data at rest is a security best practice. RDS instances must also be encrypted. If you have an existing unencrypted RDS instance, this article will guide you on how you can migrate it to an encrypted one.

Introduction

โ€

AWS provides at-read encryption for RDS instances which should be enabled to ensure the integrity of data stored within the databases.

Data encryption at rest allows your data to remain secure even when hosted on the cloud. When server side encryption is not enabled, in the event of an unauthorised access or breach of the underlying infrastructure, the integrity of your data could be violated and may present a risk. This would also violate data security compliances and could attract penalties from regulatory authorities.

In this article we will take a look at how we can migrate an unencrypted RDS database to an encrypted one.

โ€

Encrypting an unencrypted RDS database

โ€

RDS encryption is an immutable setting that must be turned on at the time of creation. To migrate a database from unencrypted to encrypted, follow these steps:

โ€

  1. Login to the AWS Management Console
  2. Navigate to KMS service and create a new CMK Key
  3. Click on the newly created CMK alias and copy the full key ARN

Click on the newly created CMK alias and copy the full key ARN4. Now the new CMK must be applied to encrypt/decrypt the RDS instance data 5. Navigate to RDS service and select the RDS database instance that you want to encrypt

  1. Click the Instance Actions button from the dashboard top menu and select Take Snapshot
  2. On the Take DB Snapshot page, enter a name for the instance snapshot in the Snapshot Name field and click Take Snapshot

On the Take DB Snapshot page, enter a name for the instance snapshot in the Snapshot Name field and click Take Snapshot8. Select the newly created snapshot and click the Copy Snapshot button from the dashboard top menu

Select the newly created snapshot and click the Copy Snapshot button from the dashboard top menu9. On the Make Copy of DB Snapshot page, perform the following steps:

  • In the New DB Snapshot Identifier field, enter a name for the new snapshot.
  • Check Copy Tags so the new snapshot can have the same tags as the source snapshot.
  • In the Master Key dropdown list, select Enter a key ARN to provide your own CMK ARN.
  • In the ARN field, paste the CMK ARN

On the Make Copy of DB Snapshot page, perform the following steps:10. Click Copy Snapshot to create an encrypted copy of the selected instance snapshot 11. Select the new snapshot copy and click the Restore Snapshot button from the dashboard top menu. This will restore the encrypted snapshot to a new database instance

Select the new snapshot copy and click the Restore Snapshot button from the dashboard top menu. This will restore the encrypted snapshot to a new database instance12. On the Restore DB Instance page, enter a unique name for the new database instance in the DB instance identifier field

On the Restore DB Instance page, enter a unique name for the new database instance in the DB instance identifier field13. Review the instance configuration details and click Restore DB Instance

โ€

The new database instance is created, you can update your application configuration to refer to the endpoint of the new database instance. Once the database endpoint is changed at your application level to point to the new instance and you have ensured that everything is working as expected, you can remove the old unencrypted database instance.

โ€

Conclusion

โ€

In this article we covered how to migrate an unencrypted database to an encrypted one via the AWS console. Keep an eye on this space for the CLI commands of this procedure in the coming few days.

โ€

***

โ€

This article is brought to you by Kloudle Academy, a free e-resource compilation, created and curated by Kloudle. Kloudle is a cloud security management platform that uses the power of automation and simplifies human requirements in cloud security. Receive alerts for Academy by subscribing here.

;