Data Pipes use KMs for all encryption.

We create 2 customer-managed KMS keys for encryption

  1. Core KMS key which encrypts

    1. RDS instance

    2. Elasticache instance

  2. Data Pipes KMS key which encrypts

    1. S3 buckets

    2. Athena workgroup

    3. SQS queues

    4. SNS topic

