CloudWatch Synthetics supports customer-managed KMS keys for encryption
Amazon CloudWatch Synthetics now allows using customer-managed AWS KMS keys for encrypting canary environment variables, providing greater control over sensitive data. This feature enhances security for regulated industries by enabling specific key management policies and auditability. It is available in all commercial AWS Regions, with options for per-region keys in multi-location canaries.
- →Customer-managed KMS keys for encrypting canary environment variables
- →Enhanced control over sensitive data in Synthetics canaries
Features (1) ›
- Customer-managed KMS keys for encrypting canary environment variables
CloudWatch Synthetics now supports using customer-managed AWS KMS keys for encrypting sensitive environment variables, giving users full control over encryption. Previously, only AWS-owned keys were used. This feature is available in all commercial AWS Regions.
Enhancements (1) ›
- Enhanced control over sensitive data in Synthetics canaries
Users can now choose to encrypt environment variables at rest using their own symmetric KMS key or encrypt individual values client-side before storage. This provides better auditability and adherence to organizational key management policies, especially for teams in regulated industries.
https://aws.amazon.com/about-aws/whats-new/2026/07/synthetics-customer-managed-keys/
Related releases
- Terraform AWS Provider v6.57.0: New EKS and Bedrock resources, deprecations Terraform AWS Provider Releases ·
- Amazon EKS 1.33 has reached end of life endoflife.date ·
- Redshift Serverless adds 3-year all-upfront pricing for cost savings AWS What's New ·
- Amazon EKS supports AWS PrivateLink for OIDC endpoint AWS What's New ·
- AWS DataSync Enhanced mode adds EFS and FSx for Lustre support AWS What's New ·
- Amazon EKS Provisioned Control Plane improves pod autoscaling speed AWS What's New ·