Skip to content

Use KMS encryption for ADF notifications #422

@Nr18

Description

@Nr18

Why

From a compliance point of view we need all SNS topics to be encrypted. The pipeline notifications topic is currently not using encryption.

Proposal

As Werner Vogels once said:

Dance Like Nobody’s Watching. Encrypt Like Everyone Is

So we should:

  • Use the AWS managed KMS key by default.
  • Make use of a Customer Managed KMS Key optional.
  • Use the default KMS key created by ADF.

Feedback?

Do you know the year Werner used that quote on stage at re:Invent? I can't remember the year...

But please contribute in this discussion!

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions