Description
Redshift encryption at rest protects the database and associated snapshots. The current CreateCluster API encrypts new provisioned clusters by default and rejects an explicit Encrypted: false. Do not assume this default change also encrypts existing clusters or snapshot restores. Check the actual resources.
Existing unencrypted clusters can use a supported transition to KMS encryption. AWS manages migration of their data to a new encrypted cluster, so plan the change with key permissions and service impact in mind.
Potential impact
- Existing unencrypted clusters and snapshots may not meet organizational encryption-at-rest requirements.
- Unsupported options or tools can cause deployment failures or leave the actual encryption state unchanged.
Remediation
- Check encryption on the real cluster and relevant snapshots, along with the KMS key and permissions. Apply current API encryption requirements to new clusters.
- Transition existing clusters through a supported tool or the
ModifyClusterAPI. The modification path incommunity.aws1.5.0 does not sendencrypted, so adding that option alone does not enable encryption. - Review snapshot handling and service impact before applying the change. Verify actual encryption and data access afterward, and maintain network permissions, database permissions and TLS separately.
Examples
Supply the password through a securely managed variable. Set redshift_node_type to a type supported by the installed community.aws module and by the Region for a single-node cluster, and configure networking and authentication for your environment.
Disabling encryption is rejected by the current API
- name: Basic cluster provisioning example
community.aws.redshift:
identifier: tf-redshift-cluster
command: create
db_name: mydb
username: foo
password: "{{ redshift_admin_password }}"
node_type: "{{ redshift_node_type }}"
cluster_type: single-node
encrypted: false
The current creation API rejects an explicit encrypted: false. This is not a deployment procedure for creating an unencrypted cluster.
Request encryption for a new cluster
- name: Basic cluster provisioning example
community.aws.redshift:
identifier: tf-redshift-cluster
command: create
db_name: mydb
username: foo
password: "{{ redshift_admin_password }}"
node_type: "{{ redshift_node_type }}"
cluster_type: single-node
encrypted: true
This explicitly requests encryption when creating a cluster. Transitioning an existing cluster to encryption requires the supported modification procedure described above.