CloudWatch Synthetics supports customer-managed KMS keys for encryption
Amazon CloudWatch Synthetics now allows using customer-managed AWS KMS keys for encrypting canary environment variables, providing greater control over sensitive data. This feature enhances security for regulated industries by enabling specific key management policies and auditability. It is available in all commercial AWS Regions, with options for per-region keys in multi-location canaries.
- →Customer-managed KMS keys for encrypting canary environment variables
- →Enhanced control over sensitive data in Synthetics canaries
Features (1) ›
- Customer-managed KMS keys for encrypting canary environment variables
CloudWatch Synthetics now supports using customer-managed AWS KMS keys for encrypting sensitive environment variables, giving users full control over encryption. Previously, only AWS-owned keys were used. This feature is available in all commercial AWS Regions.
Enhancements (1) ›
- Enhanced control over sensitive data in Synthetics canaries
Users can now choose to encrypt environment variables at rest using their own symmetric KMS key or encrypt individual values client-side before storage. This provides better auditability and adherence to organizational key management policies, especially for teams in regulated industries.
https://aws.amazon.com/about-aws/whats-new/2026/07/synthetics-customer-managed-keys/
Related releases
- Amazon Neptune 1.1.1.0 end-of-life date moved to 2026-12-04 endoflife.date ·
- Amazon Neptune 1.2.0.0 end-of-life date moved to 2026-12-04 endoflife.date ·
- Amazon Neptune 1.2.0.1 end-of-life date moved to 2026-12-04 endoflife.date ·
- Amazon Neptune 1.2.0.2 end-of-life date moved to 2026-12-04 endoflife.date ·
- Amazon Neptune 1.2.1.0 end-of-life date moved to 2026-12-04 endoflife.date ·
- Amazon Neptune 1.2.1.1 end-of-life date moved to 2026-12-04 endoflife.date ·