AWS CloudFormation
User Guide (Version )

AWS::Elasticsearch::Domain EncryptionAtRestOptions

Whether the domain should encrypt data at rest, and if so, the AWS Key Management Service (KMS) key to use. Can only be used to create a new domain, not update an existing one.

Syntax

To declare this entity in your AWS CloudFormation template, use the following syntax:

JSON

{ "Enabled" : Boolean, "KmsKeyId" : String }

YAML

Enabled: Boolean KmsKeyId: String

Properties

Enabled

Specify true to enable encryption at rest.

Required: No

Type: Boolean

Update requires: Replacement

KmsKeyId

The KMS key ID. Takes the form 1a2a3a4-1a2a-3a4a-5a6a-1a2a3a4a5a6a.

Required: No

Type: String

Update requires: Replacement

See Also

On this page: