Home icon

Securing Amazon ECS workloads on AWS Fargate with customer managed keys

Compute Blog



This article explains how to enable and use customer managed keys (CMKs) to encrypt the ephemeral storage of Amazon ECS tasks running on AWS Fargate, providing enhanced security and compliance for regulated workloads.

Specifically, the article covers:

  • Overview of AWS Fargate ephemeral storage encryption and compliance certifications
  • How to enable CMKs for Fargate ephemeral storage on new or existing ECS clusters
  • Using IAM policies to enforce encryption with CMKs
  • Auditing CMK encryption events in CloudTrail logs
  • Conclusion on meeting security requirements for Fargate workloads with CMKs


Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 10
2024
Amazon ECS on AWS Fargate now allows you to encrypt ephemeral storage with customer-managed KMS keys
Apr 3
2024
Unlocking AWS Fargate feature for attaching Amazon EBS Volumes to ECS Tasks
Jul 29
2024
Strengthening data security in AWS Step Functions with a customer-managed AWS KMS key
Jun 17
2024
AWS KMS now supports Elliptic Curve Diffie-Hellman (ECDH) key agreement

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.