Skip to content

Commit 7c6a771

Browse files
committed
add kms encryption for s3
1 parent c481de0 commit 7c6a771

1 file changed

Lines changed: 11 additions & 0 deletions

File tree

terraform/s3_dq_reports.tf

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -85,4 +85,15 @@ resource "aws_s3_bucket_policy" "data_quality_bucket_policy" {
8585
},
8686
]
8787
})
88+
}
89+
90+
resource "aws_s3_bucket_server_side_encryption_configuration" "s3_data_quality_encryption" {
91+
bucket = aws_s3_bucket.data_quality_reports_bucket.id
92+
93+
rule {
94+
apply_server_side_encryption_by_default {
95+
kms_master_key_id = data.aws_kms_key.existing_s3_encryption_key.arn
96+
sse_algorithm = "aws:kms"
97+
}
98+
}
8899
}

0 commit comments

Comments
 (0)