> For the complete documentation index, see [llms.txt](https://mariadb.com/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://mariadb.com/docs/release-notes/enterprise-server/about/mariadb-enterprise-server-differences/mariadb-enterprise-server-data-at-rest-encryption/encryption-plugins/understanding-the-amazon-web-services-aws-kms-encryption-plugin.md).

# Understanding the Amazon Web Services (AWS) KMS Encryption Plugin

## When to Use the AWS KMS Encryption Plugin?

The AWS KMS Encryption Plugin (aws\_key\_management) allows you to:

* Use [AWS KMS](https://aws.amazon.com/kms/) to manage MariaDB's encryption keys.
* Encrypt MariaDB data using those keys, including:
  * [InnoDB Data](/docs/server/server-usage/storage-engines/innodb.md)
  * [Aria Data](/docs/server/server-usage/storage-engines/aria.md)
  * [Binary Logs](/docs/server/server-management/server-monitoring-logs/binary-log.md)
  * [Galera Cluster's GCache](/docs/release-notes/enterprise-server/about/mariadb-enterprise-server-differences/mariadb-enterprise-server-data-at-rest-encryption/encrypting-galera-clusters-gcache.md)
* Rotate encryption keys.

Additional information is available [here](/docs/server/security/encryption/data-at-rest-encryption/key-management-and-encryption-plugins/aws-key-management-encryption-plugin.md).

<sub>*This page is: Copyright © 2025 MariaDB. All rights reserved.*</sub>

{% @marketo/form formid="4316" formId="4316" %}
