KMS
KMS Recommendations
As a user I am required to change my KMS once in a while and I am charged twice once for the new key and once for the old key till it is deleted.
- Many keys are not being deleted even when they are no longer used since no one knows about them.
- As long as the old key is not deleted the charges continue.
- Disabled key are still being charged.
- Invoice CUE file does not include any details on KMS which makes it more difficult.
- Finally, KMS record does not include usage details, so cannot tell when was the key last used.
Although the cost of a KMS key is about 1$ a month as with any cloud costs the totals could get quite large as your business grows.
We offer two kind of recommendations for KMS:
-
Listing all disabled keys and suggesting their deletion.
-
Listing all Keys that were created over a year ago (subject to preferences).
Disabled KMS
This recommendation identifies management events that are delivered for both member accounts and management accounts, as these will incur duplicated charges. We therefore suggest terminating trails associated with the member account.
The Recommendation for AWS CloudTrail identifies excessive Trails per member payer account and suggests their termination.
N/A
Umbrella.
No.
kms:ListKeys
kms:DescribeKey
kms:ListResourceTags
kms:ListKeyRotations
To enable KMS recommendations, make sure to add the following permission to each of the linked accounts. This is also part of the Account->Policies json file.
Old KMS
Aged Keys that were created at least 1 year ago (subject to preferences).
Aged Keys that were created at least 1 year ago (subject to preferences).
- Days To Check, default 365.
Umbrella.
No.
kms:ListKeys
kms:DescribeKey
kms:ListResourceTags
kms:ListKeyRotations
Updated over 1 year ago
