This is the new Amazon CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the Amazon CloudFormation User Guide.
AWS::Elasticsearch::Domain EncryptionAtRestOptions
Whether the domain should encrypt data at rest, and if so, the Amazon Key Management Service key to use.
Important
The AWS::Elasticsearch::Domain resource is being replaced by the AWS::OpenSearchService::Domain resource. While the legacy Elasticsearch resource
        and options are still supported, we recommend modifying your existing Cloudformation
        templates to use the new OpenSearch Service resource, which supports both OpenSearch and
        Elasticsearch. For more information about the service rename, see New resource
          types in the Amazon OpenSearch Service Developer
        Guide.
Syntax
To declare this entity in your Amazon CloudFormation template, use the following syntax:
Properties
- Enabled
- 
                    Specify trueto enable encryption at rest.Required: No Type: Boolean Update requires: No interruption 
- KmsKeyId
- 
                    The KMS key ID. Takes the form 1a2a3a4-1a2a-3a4a-5a6a-1a2a3a4a5a6a. Required if you enable encryption at rest.Required: Conditional Type: String Update requires: No interruption 
See also
- 
                    CreateDomain in the Amazon OpenSearch Service Developer Guide.