RDS instance has public access enabled

Review RDS public-access settings, omitted-value defaults, and the network conditions required for a connection.

Description

Setting publicly_accessible: true enables public access for an RDS instance, whose endpoint then resolves to a public IP address from outside its VPC. Connections still require a permitted network path and security group rules; database authentication is separate. The public-access setting alone does not establish that everyone can access the data.

When publicly_accessible is omitted, AWS API defaults depend on the engine and subnet-group configuration. Do not treat omission as equivalent to false; also check the deployed instance's settings.

Potential impact

  • A database may receive unwanted connection attempts when its network and security groups allow external connections.
  • If authentication or database permissions are also inadequate, unauthorized data access may become possible.
  • Assuming that an omitted value means private access can hide public-access settings on a running instance.

Remediation

  • Set publicly_accessible: false explicitly for an internal database and provide private connection paths for applications and administrators.
  • Restrict subnet routing and security groups to required connections. Turning off this flag does not move the instance to another subnet or block every other access path.
  • Review when the change will take effect and how it affects connections. Afterward, verify the instance's actual settings and normal application connectivity.

Examples

These examples illustrate different publicly_accessible values. They also differ in database engine and other properties, so the entire second example is not a migration procedure for the first database. Check instance types, module versions, variables, and required resources such as the cluster separately.

Before

yaml
- name: create public db instance
  community.aws.rds_instance:
    id: test-encrypted-db
    state: present
    engine: mariadb
    storage_encrypted: true
    db_instance_class: db.t2.medium
    username: "{{ username }}"
    password: "{{ password }}"
    allocated_storage: "{{ allocated_storage }}"
    publicly_accessible: true

After

yaml
- name: create private db instance
  community.aws.rds_instance:
    engine: aurora
    db_instance_identifier: ansible-test-aurora-db-instance
    instance_type: db.t2.small
    password: "{{ password }}"
    username: "{{ username }}"
    cluster_id: ansible-test-cluster
    publicly_accessible: false

Explanation:

  • Before: publicly_accessible: true enables public access. storage_encrypted: true encrypts stored data; it does not replace network access restrictions.
  • After: publicly_accessible: false disables public access. Review private network connections and other security settings separately.

References