Description
Setting publicly_accessible: true enables public access for an RDS instance, whose endpoint then resolves to a public IP address from outside its VPC. Connections still require a permitted network path and security group rules; database authentication is separate. The public-access setting alone does not establish that everyone can access the data.
When publicly_accessible is omitted, AWS API defaults depend on the engine and subnet-group configuration. Do not treat omission as equivalent to false; also check the deployed instance's settings.
Potential impact
- A database may receive unwanted connection attempts when its network and security groups allow external connections.
- If authentication or database permissions are also inadequate, unauthorized data access may become possible.
- Assuming that an omitted value means private access can hide public-access settings on a running instance.
Remediation
- Set
publicly_accessible: falseexplicitly for an internal database and provide private connection paths for applications and administrators. - Restrict subnet routing and security groups to required connections. Turning off this flag does not move the instance to another subnet or block every other access path.
- Review when the change will take effect and how it affects connections. Afterward, verify the instance's actual settings and normal application connectivity.
Examples
These examples illustrate different publicly_accessible values. They also differ in database engine and other properties, so the entire second example is not a migration procedure for the first database. Check instance types, module versions, variables, and required resources such as the cluster separately.
Before
- name: create public db instance
community.aws.rds_instance:
id: test-encrypted-db
state: present
engine: mariadb
storage_encrypted: true
db_instance_class: db.t2.medium
username: "{{ username }}"
password: "{{ password }}"
allocated_storage: "{{ allocated_storage }}"
publicly_accessible: true
After
- name: create private db instance
community.aws.rds_instance:
engine: aurora
db_instance_identifier: ansible-test-aurora-db-instance
instance_type: db.t2.small
password: "{{ password }}"
username: "{{ username }}"
cluster_id: ansible-test-cluster
publicly_accessible: false
Explanation:
- Before:
publicly_accessible: trueenables public access.storage_encrypted: trueencrypts stored data; it does not replace network access restrictions. - After:
publicly_accessible: falsedisables public access. Review private network connections and other security settings separately.