A config rule that checks whether Amazon Elastic Kubernetes Service clusters are configured to have Kubernetes secrets encrypted using AWS Key Management Service (KMS) keys.

This config rule supports the following parameters:

  • kmsKeyArns
    • Required: No
    • Type: CSV
    • Description:Comma separated list of Amazon Resource Name (ARN) of the KMS key that should be used for encrypted secrets in an EKS cluster.

CloudFormation Template