Description
Redshift's public-access option is used for connections to a cluster over the internet. If routing and security groups also allow the connection, clients beyond the intended audience may attempt to connect. Network reachability does not bypass database authentication or permissions.
Potential impact
- An unnecessary public path can broaden exposure to sign-in attempts or vulnerability exploitation.
- Weak credential or database-permission management can lead to unintended data access.
Remediation
- If public connections are unnecessary, prepare the clients' private paths and restricted inbound rules before disabling public access.
- Use a supported update method for existing clusters. In
community.aws11.1.0, rerunningcreatefor an existing identifier or usingmodifydoes not changepublicly_accessible. AWS'sModifyClusterAPI supports the change. - Verify the deployed setting and required client connections, and test that unapproved connections are blocked. Review authentication, least privilege and transport protection too.
Examples
These alternatives create a new single-node cluster. Set redshift_single_node_type to a type supported by both the module and AWS, and supply redshift_admin_password securely from a secret store. Prepare the actual Region, subnet and security groups too. Rerunning these tasks does not update an existing cluster's public setting.
Before
- name: Basic cluster provisioning example
community.aws.redshift:
command: create
node_type: "{{ redshift_single_node_type }}"
cluster_type: single-node
identifier: new-cluster
username: cluster_admin
password: "{{ redshift_admin_password }}"
encrypted: true
publicly_accessible: yes
The task requests public access for a new cluster. External connectivity still depends on network paths and security groups.
After
- name: Basic cluster provisioning example
community.aws.redshift:
command: create
node_type: "{{ redshift_single_node_type }}"
cluster_type: single-node
identifier: new-cluster
username: cluster_admin
password: "{{ redshift_admin_password }}"
encrypted: true
publicly_accessible: false
Public access is disabled for the new cluster. Verify that required clients can connect through private paths.