aws / aws/containers-roadmap

[EKS] [request]: support for associating an EKS control plane cloudwatch log group with a customer managed kMS key

Open
#1,713 1 comment 2 reactions 0 assignees View on GitHub
EKS Proposed
Dominant language
Shell
Stars
5.4k
Forks
334
PR merge metrics
No merged PRs in 30d

Description

**Tell us about your request**
Currently, there does not seem to be any way to automatically encrypt the log group that is created when logging is enabled for an EKS cluster. It seems like the only solution is to enable encryption on the log group after it is created.

**Which service(s) is this request for?**
EKS, Cloudwatch Logs

**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
We would like to be able to choose a KMS CMK to use when enabling logging for an EKS cluster. You can encrypt the resulting log group after it is created, but there is no way to permanently associate an EKS log group with a KMS key.

**Are you currently working around this issue?**
Create the EKS cluster, enable logging, and then separately encrypt the cloudwatch log group that was created for the cluster.

Contributor guide

Open the contributing guide

Research direction

No repository files, tests, or entry points are identified. Start by reviewing the EKS logging request and its current workaround of encrypting the created CloudWatch log group afterward. Done means enabling EKS logging with a customer-managed KMS key associated with the resulting log group.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, kubernetes
Domain
cloud, observability, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.