Review ElastiCache VPC subnet selection

Verify the cache’s actual VPC and subnets, and allow access only from required applications.

Description

Explicitly choosing an ElastiCache VPC and subnet group helps manage network boundaries and access policies consistently. Omitting cache_subnet_group can still select a default VPC, so omission alone does not mean deployment outside a VPC. Check the actual placement and associated security groups.

Potential impact

  • The cache may be placed in a network the organization did not intend.
  • Application connections may fail, or connections may be attempted from a broader network scope than necessary.

Remediation

  • Prepare a cache subnet group using subnets in the intended VPC and select it through cache_subnet_group.
  • Allow only the required applications’ cache connections in the associated VPC security groups. Verify actual routes and access results, and plan data and connection cutover when moving an existing cache.

Examples

These historical Memcached examples compare subnet group selection. For new deployments, use supported engine versions and node types with an actual Availability Zone. Also verify that the group named default contains subnets in the intended VPC.

Before

yaml
- name: ElastiCache 생성
  community.aws.elasticache:
    name: test-please-delete
    state: present
    engine: memcached
    cache_engine_version: 1.4.14
    node_type: cache.m1.small
    num_nodes: 1
    cache_port: 11211
    zone: us-east-1d

No subnet group is explicitly selected. Check the effective default; this does not mean deployment outside a VPC.

After

yaml
- name: ElastiCache 생성
  community.aws.elasticache:
    name: test-please-delete
    state: present
    engine: memcached
    cache_engine_version: 1.4.14
    node_type: cache.m1.small
    num_nodes: 1
    cache_port: 11211
    cache_subnet_group: default
    zone: us-east-1d

This selects the subnet group named default. Its name alone does not guarantee isolation or restricted security-group access.

References