- Adds support for AWS KMS customer‑managed keys to encrypt data at rest for InfluxDB 2, read replicas, and InfluxDB 3 clusters.
- Key must be selected during resource creation and cannot be changed later; must reside in the same AWS account and region.
- Available via console, CLI, and API with no extra Timestream charge (standard KMS fees apply).