AWS Security ChangesHomeSearch

AWS documentdb: Clarify KMS permissions for DocumentDB elastic encryption

Service: documentdb · 2026-07-29 · Documentation high

File: documentdb/latest/devguide/elastic-encryption.md · Type: encryption

Summary

Updated KMS permission descriptions to correctly reference 'Amazon DocumentDB elastic clusters' instead of 'Docdb Elastic' and fixed service-specific examples.

Security assessment

The evidence line clarifies that Amazon DocumentDB requires kms:Decrypt permission to access encrypted data, reinforcing proper key management configuration to prevent unauthorized data access.

Evidence

+  * [`kms:Decrypt`](https://docs.aws.amazon.com/kms/latest/APIReference/API_Decrypt.html) – Allows Amazon DocumentDB elastic clusters to use the stored encrypted data key to access encrypted data.

Diff

diff --git a/documentdb/latest/devguide/elastic-encryption.md b/documentdb/latest/devguide/elastic-encryption.md
index f8b51878d..b59d86bce 100644
--- a//documentdb/latest/devguide/elastic-encryption.md
+++ b//documentdb/latest/devguide/elastic-encryption.md
@@ -73 +73 @@ Amazon DocumentDB elastic clusters require the grant to use your customer manage
-  * Send `DescribeKey` requests to AWS KMS to verify that the symmetric customer managed KMS key ID, entered when creating a tracker or geofence collection, is valid.
+  * Send `DescribeKey` requests to AWS KMS to verify that the symmetric customer managed key ID, entered when creating an elastic cluster, is valid.
@@ -90 +90 @@ You can create a symmetric customer managed key by using the AWS Management Cons
-Follow the steps for [Creating symmetric customer managed key](https://docs.aws.amazon.com/kms/latest/developerguide/create-keys.html) in the _AWS Key Management Service Developer Guide_.
+Follow the steps for [Creating a symmetric customer managed key](https://docs.aws.amazon.com/kms/latest/developerguide/create-keys.html) in the _AWS Key Management Service Developer Guide_.
@@ -98 +98 @@ To use your customer managed key with Amazon DocumentDB elastic cluster resource
-  * [`kms:CreateGrant`](https://docs.aws.amazon.com/kms/latest/APIReference/API_CreateGrant.html) – Adds a grant to a customer managed key. Grants control access to a specified KMS key, which allows access to grant operations Amazon Location Service requires. For more information about using grants, see [Grants in AWS KMS](https://docs.aws.amazon.com/kms/latest/developerguide/grants.html) in the _AWS Key Management Service Developer Guide_.
+  * [`kms:CreateGrant`](https://docs.aws.amazon.com/kms/latest/APIReference/API_CreateGrant.html) – Adds a grant to a customer managed key. Grants control access to a specified KMS key, which allows access to the grant operations that Amazon DocumentDB elastic clusters require. For more information about using grants, see [Grants in AWS KMS](https://docs.aws.amazon.com/kms/latest/developerguide/grants.html) in the _AWS Key Management Service Developer Guide_.
@@ -100 +100 @@ To use your customer managed key with Amazon DocumentDB elastic cluster resource
-  * [`kms:DescribeKey`](https://docs.aws.amazon.com/kms/latest/APIReference/API_DescribeKey.html) – Provides the customer managed key details to allow Docdb Elastic to validate the key.
+  * [`kms:DescribeKey`](https://docs.aws.amazon.com/kms/latest/APIReference/API_DescribeKey.html) – Provides the customer managed key details to allow Amazon DocumentDB elastic clusters to validate the key.
@@ -102 +102 @@ To use your customer managed key with Amazon DocumentDB elastic cluster resource
-  * [`kms:Decrypt`](https://docs.aws.amazon.com/kms/latest/APIReference/API_Decrypt.html) – Allows Docdb Elastic to use the stored encrypted data key to access encrypted data.
+  * [`kms:Decrypt`](https://docs.aws.amazon.com/kms/latest/APIReference/API_Decrypt.html) – Allows Amazon DocumentDB elastic clusters to use the stored encrypted data key to access encrypted data.
@@ -104 +104 @@ To use your customer managed key with Amazon DocumentDB elastic cluster resource
-  * [`kms:GenerateDataKey`](https://docs.aws.amazon.com/kms/latest/APIReference/API_GenerateDataKey.html) – Allows Docdb Elastic to generate an encrypted data key and store it because the data key isn't immediately used to encrypt.
+  * [`kms:GenerateDataKey`](https://docs.aws.amazon.com/kms/latest/APIReference/API_GenerateDataKey.html) – Allows Amazon DocumentDB elastic clusters to generate an encrypted data key and store it because the data key isn't immediately used to encrypt.
@@ -121 +121 @@ For more information, see [Allowing users in other accounts to use a KMS key](ht
-When you use an AWS KMS key customer managed key with your Docdb Elastic resources, you can use AWS CloudTrail or Amazon CloudWatch Logs to track requests that Docdb Elastic sends to AWS KMS.
+When you use a customer managed key with your Amazon DocumentDB elastic cluster resources, you can use AWS CloudTrail or Amazon CloudWatch Logs to track requests that Amazon DocumentDB elastic clusters send to AWS KMS.