Review RDS ports and access controls

Manage database port selection separately from actual access controls.

Description

Using an engine’s default port is not itself a vulnerability. For example, MySQL, MariaDB and Aurora MySQL default to 3306, while PostgreSQL and Aurora PostgreSQL default to 5432. Changing the port cannot prevent service discovery or unauthorized access; actual risk depends on network scope, authentication and permissions.

Potential impact

  • Broad network access can expose a database to unnecessary connection attempts.
  • Treating a port change as access control, or failing to update connection settings, can create security gaps or service interruptions.

Remediation

  • Restrict access to required clients through security groups, subnets and routing, and apply database authentication, least privilege and transport encryption.
  • If operating requirements call for another port, use a supported value and update clients, firewalls and monitoring together. Aurora’s port is configured on the cluster rather than individual instances. Check the effect on existing connections and plan the transition.

Examples

These partial examples compare the port on an Aurora MySQL cluster. Supply administrator credentials securely and separately prepare the actual network, security groups and cluster instances.

Before

yaml
- name: Aurora 클러스터 포트 설정
  amazon.aws.rds_cluster:
    engine: aurora-mysql
    password: "{{ password }}"
    username: "{{ username }}"
    cluster_id: ansible-test-cluster
    backup_retention_period: 7
    port: 3306

This specifies Aurora MySQL’s default port, 3306. A default port alone does not make the database public or weaken its authentication.

After

yaml
- name: Aurora 클러스터 포트 설정
  amazon.aws.rds_cluster:
    engine: aurora-mysql
    password: "{{ password }}"
    username: "{{ username }}"
    cluster_id: ansible-test-cluster
    backup_retention_period: 7
    port: 3307

This changes the cluster port to 3307. Network and database permissions remain unchanged, so separate access controls and client connection updates are still required.

References