EncryptionAtRestOptions - Amazon OpenSearch Service


Specifies whether the domain should encrypt data at rest, and if so, the Key Management Service (KMS) key to use. Can only be used when creating a new domain or enabling encryption at rest for the first time on an existing domain. You can't modify this parameter after it's already been specified.



True to enable encryption at rest.

Type: Boolean

Required: No


The KMS key ID. Takes the form 1a2a3a4-1a2a-3a4a-5a6a-1a2a3a4a5a6a.

Type: String

Length Constraints: Minimum length of 1. Maximum length of 500.

Pattern: .*

Required: No

