Description
Setting backup_retention_period to 0 disables automated backups on an ordinary RDS DB instance. This does not apply to Aurora, where automated backups cannot be disabled and retention is managed at the cluster level.
Potential impact
Point-in-time recovery through automated backups is unavailable, reducing recovery options after data loss. Separately created manual snapshots are not removed by this setting.
Remediation
Set a supported retention period of at least one day that meets recovery objectives. Changing between zero and a nonzero value can cause an outage, so plan the change and test restoration.
Examples
The examples set retention to zero or five days on an existing RDS instance other than Aurora. Other settings needed for creation are omitted.
Before
- name: Set RDS instance backup retention
amazon.aws.rds_instance:
db_instance_identifier: ansible-test-db-instance
backup_retention_period: 0
After
- name: Set RDS instance backup retention
amazon.aws.rds_instance:
db_instance_identifier: ansible-test-db-instance
backup_retention_period: 5