Home icon

Options for changing AWS KMS encryption key for Amazon RDS databases

Database Blog



This article outlines five methods for changing AWS KMS encryption keys on Amazon RDS and Aurora databases, comparing effort, downtime, and engine support for each approach.

  • Snapshot and restore: Low effort, minutes-to-hours downtime, supports all RDS engines
  • AWS DMS: Medium effort, seconds-to-minutes downtime, supports all RDS engines
  • Native database replication: Medium-to-high effort, seconds-to-minutes downtime, MySQL/MariaDB/PostgreSQL only
  • Aurora cluster clones: Medium-to-high effort, minutes downtime, Aurora MySQL/PostgreSQL only
  • Aurora read replicas: Low-to-medium effort, seconds-to-minutes downtime, Aurora MySQL/PostgreSQL only
  • Two KMS key types: AWS managed (default aws/rds) and customer managed keys
  • Monitor with CloudWatch and CloudTrail; implement AWS Config rules for compliance
  • Retain original instance until confident in migration success; consider data retention policies

Choose the method based on downtime tolerance, database size, technical expertise, and engine capabilities. Test thoroughly in non-production environments before production implementation.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Mar 12
2024
Choose the right type of AWS KMS key to encrypt Amazon RDS and Aurora Global Database
May 4
2026
Managing SQL Server Encryption Keys Across AWS Regions for Disaster Recovery
Apr 3
2026
AWS Secrets Manager console now supports custom input for AWS KMS keys
Apr 3
2026
How AWS KMS and AWS Encryption SDK overcome symmetric encryption bounds

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.