Description
Minor-version upgrades can include security and stability fixes. Disabling automatic upgrades while delaying manual patches can prolong exposure to an old engine version. Omitting the setting does not establish that automatic upgrades are disabled; check the effective instance and cluster settings.
Potential impact
- Delayed security patches can leave known vulnerabilities exposed for longer.
- Missing bug fixes and inconsistent instance versions can complicate operations.
Remediation
- Set
auto_minor_version_upgrade: truewhen supported by the engine and appropriate for the operating policy. For Aurora, check the related cluster and instance settings together. - Automatic upgrades apply minor releases that AWS designates for automatic installation according to the maintenance schedule. They do not immediately install every latest version. Plan testing and maintenance, and define patch deadlines when managing upgrades manually.
Examples
Use instance classes supported by the collection and Region. The Aurora instance joins an existing Aurora MySQL cluster, which manages its administrator credentials. Also check class and engine-version compatibility for the MariaDB example.
Before
- name: Aurora 인스턴스 생성
community.aws.rds_instance:
engine: aurora-mysql
db_instance_identifier: ansible-test-aurora-db-instance
instance_type: "{{ aurora_instance_class }}"
cluster_id: ansible-test-cluster
auto_minor_version_upgrade: false
- name: MariaDB 인스턴스 생성
community.aws.rds_instance:
id: test-encrypted-db
state: present
engine: mariadb
storage_encrypted: true
db_instance_class: db.t2.medium
username: "{{ username }}"
password: "{{ password }}"
allocated_storage: "{{ allocated_storage }}"
The Aurora task disables automatic upgrades. Omitting the setting from the MariaDB task does not establish its effective value.
After
- name: Aurora 인스턴스 생성
community.aws.rds_instance:
engine: aurora-mysql
db_instance_identifier: ansible-test-aurora-db-instance
instance_type: "{{ aurora_instance_class }}"
cluster_id: ansible-test-cluster
auto_minor_version_upgrade: true
This enables automatic minor upgrades for the instance. Check the cluster setting, eligible version and actual schedule as well.