AWS Lambda adds customer-managed key encryption to durable functions
Amazon Web Services has introduced support for customer-managed encryption keys for Lambda durable functions, giving organizations greater control over how application state data is protected. The feature enables developers to encrypt durable functions state data using customer-managed keys in AWS Key Management Service (AWS KMS) instead of AWS-managed encryption keys.
The capability is designed to help organizations meet internal security policies and regulatory requirements by allowing them to create, rotate and manage encryption keys while maintaining control over access permissions and audit processes. Users can now configure a customer-managed key for durable execution data, giving you control over key rotation and who can access execution history and state.
The company said customer-managed key support is intended for organizations running business-critical serverless applications that require enhanced data protection and compliance controls. By integrating with AWS KMS, developers can apply consistent encryption policies across serverless workloads and other AWS services. The feature is available in all AWS Regions where Lambda durable functions is available.
The "AWS Release Radar" blog is researched, fact-checked, edited and updated by the editors of AWSInsider.net, with writing assistance from AI. To submit your channel company's press release for consideration, contact Ammaarah Mohamed.
Posted by AWS Editors on 07/22/2026