[EKS] [request]: support for associating an EKS control plane cloudwatch log group with a customer managed kMS key
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
**Tell us about your request**
Currently, there does not seem to be any way to automatically encrypt the log group that is created when logging is enabled for an EKS cluster. It seems like the only solution is to enable encryption on the log group after it is created.
**Which service(s) is this request for?**
EKS, Cloudwatch Logs
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
We would like to be able to choose a KMS CMK to use when enabling logging for an EKS cluster. You can encrypt the resulting log group after it is created, but there is no way to permanently associate an EKS log group with a KMS key.
**Are you currently working around this issue?**
Create the EKS cluster, enable logging, and then separately encrypt the cloudwatch log group that was created for the cluster.
Contributor guide
Research direction
No repository files, tests, or entry points are identified. Start by reviewing the EKS logging request and its current workaround of encrypting the created CloudWatch log group afterward. Done means enabling EKS logging with a customer-managed KMS key associated with the resulting log group.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, kubernetes
- Domain
- cloud, observability, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100