AWS Security ChangesHomeSearch

AWS ebs: Clarify Outpost snapshot encryption key behavior

Service: ebs · 2026-09-27 · Documentation low

File: ebs/latest/userguide/snapshots-outposts.md · Type: encryption

Summary

Condenses the Outpost local snapshot notes, stating snapshots are encrypted by default (unencrypted not supported), volumes from local snapshots use the same KMS key as the source snapshot, and the key can be changed when copying a local snapshot.

Security assessment

The edit restates and clarifies encryption requirements and KMS key behavior for Outpost snapshots, which is encryption best-practice documentation rather than a vulnerability remediation.

Evidence

+  * Snapshots stored on an Outpost are encrypted by default. Unencrypted snapshots are not supported. When you create a volume on an Outpost from a local snapshot, the volume is encrypted using the same KMS key as the source snapshot. However, you can change the encryption key when you copy a local snapshot.

Diff

diff --git a/ebs/latest/userguide/snapshots-outposts.md b/ebs/latest/userguide/snapshots-outposts.md
index e6b84581e..d6c92e074 100644
--- a//ebs/latest/userguide/snapshots-outposts.md
+++ b//ebs/latest/userguide/snapshots-outposts.md
@@ -107,3 +107 @@ Keep the following in mind when working with local snapshots.
-  * Snapshots stored on an Outpost are encrypted by default. Unencrypted snapshots are not supported. Snapshots that are created on an Outpost and snapshots that are copied to an Outpost are encrypted using the default KMS key for the Region or a different KMS key that you specify at the time of the request.
-
-  * When you create a volume on an Outpost from a local snapshot, you cannot re-encrypt the volume using a different KMS key. Volumes created from local snapshots must be encrypted using the same KMS key as the source snapshot.
+  * Snapshots stored on an Outpost are encrypted by default. Unencrypted snapshots are not supported. When you create a volume on an Outpost from a local snapshot, the volume is encrypted using the same KMS key as the source snapshot. However, you can change the encryption key when you copy a local snapshot.