From b8755390bab5c9adc24db30e556164bafcd8dddc Mon Sep 17 00:00:00 2001 From: Ian Howell Date: Fri, 19 Jul 2024 10:50:14 +0100 Subject: [PATCH] Change SSE for S3 bucket from "aws:kms" to "AES256" so that cross account decryption of files can take place. --- terraform/deployments/opensearch/s3.tf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/terraform/deployments/opensearch/s3.tf b/terraform/deployments/opensearch/s3.tf index 135f0542b..e1c95d7e8 100644 --- a/terraform/deployments/opensearch/s3.tf +++ b/terraform/deployments/opensearch/s3.tf @@ -27,7 +27,7 @@ resource "aws_s3_bucket_server_side_encryption_configuration" "opensearch_snapsh bucket = aws_s3_bucket.opensearch_snapshot.id rule { apply_server_side_encryption_by_default { - sse_algorithm = "aws:kms" + sse_algorithm = "AES256" } } }