Redshift encryption settings need review

Check actual Redshift cluster and snapshot encryption, and apply the required KMS encryption through supported tools.

Description

Redshift encryption at rest protects the database and associated snapshots. The current CreateCluster API encrypts new provisioned clusters by default and rejects an explicit Encrypted: false. Do not assume this default change also encrypts existing clusters or snapshot restores. Check the actual resources.

Existing unencrypted clusters can use a supported transition to KMS encryption. AWS manages migration of their data to a new encrypted cluster, so plan the change with key permissions and service impact in mind.

Potential impact

  • Existing unencrypted clusters and snapshots may not meet organizational encryption-at-rest requirements.
  • Unsupported options or tools can cause deployment failures or leave the actual encryption state unchanged.

Remediation

  • Check encryption on the real cluster and relevant snapshots, along with the KMS key and permissions. Apply current API encryption requirements to new clusters.
  • Transition existing clusters through a supported tool or the ModifyCluster API. The modification path in community.aws 1.5.0 does not send encrypted, so adding that option alone does not enable encryption.
  • Review snapshot handling and service impact before applying the change. Verify actual encryption and data access afterward, and maintain network permissions, database permissions and TLS separately.

Examples

Supply the password through a securely managed variable. Set redshift_node_type to a type supported by the installed community.aws module and by the Region for a single-node cluster, and configure networking and authentication for your environment.

Disabling encryption is rejected by the current API

yaml
- name: Basic cluster provisioning example
  community.aws.redshift:
    identifier: tf-redshift-cluster
    command: create
    db_name: mydb
    username: foo
    password: "{{ redshift_admin_password }}"
    node_type: "{{ redshift_node_type }}"
    cluster_type: single-node
    encrypted: false

The current creation API rejects an explicit encrypted: false. This is not a deployment procedure for creating an unencrypted cluster.

Request encryption for a new cluster

yaml
- name: Basic cluster provisioning example
  community.aws.redshift:
    identifier: tf-redshift-cluster
    command: create
    db_name: mydb
    username: foo
    password: "{{ redshift_admin_password }}"
    node_type: "{{ redshift_node_type }}"
    cluster_type: single-node
    encrypted: true

This explicitly requests encryption when creating a cluster. Transitioning an existing cluster to encryption requires the supported modification procedure described above.

References