Description
A cache engine that is unsupported or lacks required security updates can create maintenance and security-response problems. Identify the deployed engine and actual version, then compare them with AWS support and your requirements. Do not apply a Redis version requirement to Memcached.
An engine version alone does not establish PCI DSS or other compliance. Review the applicable service scope and customer-managed controls such as encryption, authentication and access restrictions.
Potential impact
- Missing required updates can leave known security issues or operational defects unresolved.
- Upgrading without compatibility checks can disrupt cache connections or application behavior.
Remediation
- Select a version and upgrade path supported for the actual engine, Region and node type. Do not use a version number from another engine.
- Test client and parameter compatibility, and prepare data recovery or cache-rebuild procedures. Review encryption and authentication requirements separately.
- Check when your module applies changes.
community.aws11.1.0 requests immediate application of version changes; assess maintenance and connection impacts, then verify the deployed version.
Examples
These alternatives change the version of an existing Memcached configuration. Set cache_node_type to a supported node type and approved_memcached_version to a real Memcached version whose compatibility you have checked. Network and authentication settings for the cluster are required separately.
Before
- name: Basic example
community.aws.elasticache:
name: test-please-delete
state: present
engine: memcached
cache_engine_version: 1.4.14
node_type: "{{ cache_node_type }}"
num_nodes: 1
The configuration names the older 1.4.14 version. Do not reuse it for a new deployment without checking current support and update requirements.
After
- name: Basic example
community.aws.elasticache:
name: test-please-delete
state: present
engine: memcached
cache_engine_version: "{{ approved_memcached_version }}"
node_type: "{{ cache_node_type }}"
num_nodes: 1
The chosen Memcached version is explicit. Verify how the existing cluster with that name is modified, that the upgrade path is supported, and that the change actually takes effect.
References
- CWE-665
- Ansible community.aws.elasticache documentation
- Ansible community.aws 11.1.0 ElastiCache implementation
- AWS's 2018 ElastiCache for Redis PCI DSS announcement
- Current ElastiCache compliance scope and responsibilities
- Supported engine versions
- ElastiCache engine version management
- Considerations when changing versions