AWS Security ChangesHomeSearch

AWS AmazonRDS: Document final DB snapshot for inaccessible KMS key state

Service: AmazonRDS · 2026-09-27 · Documentation medium

File: AmazonRDS/latest/UserGuide/Overview.Encryption.md · Type: encryption

Summary

Explains that RDS automatically creates a final manual DB snapshot when a DB instance transitions to the inaccessible-encryption-credentials state, including conditions, retention, charges, and restore steps.

Security assessment

The change documents encryption-key-related recovery behavior (final snapshot creation when a KMS key becomes inaccessible) and how to restore it, which is security-relevant data-protection guidance but does not address a specific vulnerability or CVE.

Evidence

A DB instance in the `inaccessible-encryption-credentials` state can't be recovered in place, so Amazon RDS automatically creates a final DB snapshot when a DB instance transitions to this state.

Diff

diff --git a/AmazonRDS/latest/UserGuide/Overview.Encryption.md b/AmazonRDS/latest/UserGuide/Overview.Encryption.md
index 8297da009..c9d6a021f 100644
--- a//AmazonRDS/latest/UserGuide/Overview.Encryption.md
+++ b//AmazonRDS/latest/UserGuide/Overview.Encryption.md
@@ -73 +73 @@ The `inaccessible-encryption-credentials-recoverable` state only applies to DB i
-If the DB instance isn't recovered within seven days, it goes into the terminal `inaccessible-encryption-credentials` state. In this state, the DB instance is not usable anymore and you can only restore the DB instance from a backup. We strongly recommend that you always turn on backups for encrypted DB instances to guard against the loss of encrypted data in your databases.
+If the DB instance isn't recovered within seven days, it goes into the terminal `inaccessible-encryption-credentials` state. In this state, the DB instance is no longer usable and you can only restore it from a DB snapshot or backup.
@@ -78,0 +79,62 @@ DB instances with disabled backups remain available until the volumes are detach
+A DB instance in the `inaccessible-encryption-credentials` state can't be recovered in place, so Amazon RDS automatically creates a final DB snapshot when a DB instance transitions to this state. This is similar to the final snapshot that you can request when you delete a DB instance.
+
+The snapshot captures data written after your most recent automated backup. This includes writes made while the KMS key was inaccessible. You can use the snapshot to recover data that would otherwise be lost. Amazon RDS creates it as a manual DB snapshot named `rds-final:`db-instance-identifier`-`resource-id``, and it appears alongside your other DB snapshots.
+
+The final snapshot is retained until you delete it, and it incurs backup storage charges in the same way as a manual DB snapshot. Because charges continue until you delete it, delete the snapshot as soon as you no longer need it. For more information, see [Amazon RDS pricing](https://aws.amazon.com/rds/pricing/).
+
+Amazon RDS attempts to create a final snapshot when a DB instance transitions to the `inaccessible-encryption-credentials` state in any of the following situations:
+
+  * The KMS key becomes inaccessible and the DB instance can't be stopped, so it moves directly to the `inaccessible-encryption-credentials` state. This situation includes read replicas and DB instances that have read replicas.
+
+  * The DB instance remains in the `inaccessible-encryption-credentials-recoverable` state for seven days without being recovered.
+
+  * The DB instance requires an operation that Amazon RDS can't complete because the KMS key is inaccessible. Examples include replacing the underlying host and scaling storage.
+
+
+
+
+Amazon RDS creates the final snapshot only when all of the following are true for the DB instance:
+
+  * The DB instance has data volumes attached. A DB instance with no attached storage, such as one that failed during creation or is already being deleted, has no data to capture.
+
+  * The DB instance isn't a member of a Multi-AZ DB cluster or an Aurora DB cluster. These use cluster-level backups instead of individual instance snapshots.
+
+  * The data of the DB instance is complete and not changing. Amazon RDS doesn't create a final snapshot while a DB instance is in any of the following states:
+
+    * Being created
+
+    * Being restored from a DB snapshot or backup
+
+    * Being migrated
+
+    * Having transaction logs replayed
+
+    * Being patched offline as part of a restore
+
+    * Being prepared or configured as a read replica
+
+
+
+
+Automated backups don't need to be turned on. Amazon RDS also creates a final snapshot for DB instances on AWS Outposts, and for DB instances in other terminal states as long as their storage is intact.
+
+To restore from the final snapshot, first re-enable the KMS key, because the snapshot is encrypted with the same key as the source DB instance. For more information, see [AWS KMS key management](./Overview.Encryption.Keys.html). Then restore the snapshot as you would any other DB snapshot. For the full list of parameters, see [restore-db-instance-from-db-snapshot](https://docs.aws.amazon.com/cli/latest/reference/rds/restore-db-instance-from-db-snapshot.html) in the _AWS CLI Command Reference_.
+
+###### Example Restore a DB instance from the final DB snapshot
+
+For Linux, macOS, or Unix:
+    
+    
+    aws rds restore-db-instance-from-db-snapshot \
+        --db-instance-identifier mydb-restored \
+        --db-snapshot-identifier rds-final:mydb-db-abcdefghijklmnop
+
+For Windows:
+    
+    
+    aws rds restore-db-instance-from-db-snapshot ^
+        --db-instance-identifier mydb-restored ^
+        --db-snapshot-identifier rds-final:mydb-db-abcdefghijklmnop
+
+Although automated backups aren't required, turn them on for encrypted DB instances so that point-in-time recovery is available in addition to the final snapshot.
+