Description
Using an engine’s default port is not itself a vulnerability. For example, MySQL, MariaDB and Aurora MySQL default to 3306, while PostgreSQL and Aurora PostgreSQL default to 5432. Changing the port cannot prevent service discovery or unauthorized access; actual risk depends on network scope, authentication and permissions.
Potential impact
- Broad network access can expose a database to unnecessary connection attempts.
- Treating a port change as access control, or failing to update connection settings, can create security gaps or service interruptions.
Remediation
- Restrict access to required clients through security groups, subnets and routing, and apply database authentication, least privilege and transport encryption.
- If operating requirements call for another port, use a supported value and update clients, firewalls and monitoring together. Aurora’s port is configured on the cluster rather than individual instances. Check the effect on existing connections and plan the transition.
Examples
These partial examples compare the port on an Aurora MySQL cluster. Supply administrator credentials securely and separately prepare the actual network, security groups and cluster instances.
Before
- name: Aurora 클러스터 포트 설정
amazon.aws.rds_cluster:
engine: aurora-mysql
password: "{{ password }}"
username: "{{ username }}"
cluster_id: ansible-test-cluster
backup_retention_period: 7
port: 3306
This specifies Aurora MySQL’s default port, 3306. A default port alone does not make the database public or weaken its authentication.
After
- name: Aurora 클러스터 포트 설정
amazon.aws.rds_cluster:
engine: aurora-mysql
password: "{{ password }}"
username: "{{ username }}"
cluster_id: ansible-test-cluster
backup_retention_period: 7
port: 3307
This changes the cluster port to 3307. Network and database permissions remain unchanged, so separate access controls and client connection updates are still required.