Skip to main content

Amazon Timestream for InfluxDB now supports customer managed keys

Posted on: Aug 20, 2026

Amazon Timestream for InfluxDB now supports Amazon Key Management Service (KMS) customer managed keys for encrypting data at rest in InfluxDB 2 database instances and InfluxDB 3 clusters. Select a symmetric KMS key when creating a database resource through the Amazon Timestream console, Amazon Command Line Interface (CLI), or Timestream for InfluxDB application programming interface (API).

Timestream for InfluxDB uses the selected key to encrypt the underlying database storage. The key must be in the same Amazon Web Services account and Region as the database resource. You specify the key during resource creation, and you cannot change the key after the resource is created. Customer managed keys give you control over key policies, rotation, and access while helping you meet organizational encryption and audit requirements.

Customer managed key support is available in the Amazon Web Services China (Beijing) Region, operated by Sinnet, and the Amazon Web Services China (Ningxia) Region, operated by NWCD. There is no additional Timestream for InfluxDB charge for using customer managed keys. Standard KMS charges apply. To get started, open the Amazon Timestream console. For setup requirements and supported resources, see the Amazon Timestream for InfluxDB documentation. For service pricing, see the Amazon Timestream pricing page.