Skip to content

Control Tower logs encryption #1031

@senyberg

Description

@senyberg

Is your feature request related to a problem? Please describe.
Currently you cannot set a CMK for Cloudtrail or Config log buckets through LZA:

controlTower:
  enable: true
  landingZone:
    version: "4.0"
    logging:
      loggingBucketRetentionDays: 180
      accessLoggingBucketRetentionDays: 1825

This creates the buckets used by CT, but encrypts them with SSE-S3

Describe the feature you'd like
Add a way to use own CMK's to encrypt the log buckets, separate for Config and Cloudtrail buckets.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions