Redshift configuration enables public access

Review whether Redshift needs public access, alongside private connection paths, restricted inbound rules and database authentication.

Description

Redshift's public-access option is used for connections to a cluster over the internet. If routing and security groups also allow the connection, clients beyond the intended audience may attempt to connect. Network reachability does not bypass database authentication or permissions.

Potential impact

  • An unnecessary public path can broaden exposure to sign-in attempts or vulnerability exploitation.
  • Weak credential or database-permission management can lead to unintended data access.

Remediation

  • If public connections are unnecessary, prepare the clients' private paths and restricted inbound rules before disabling public access.
  • Use a supported update method for existing clusters. In community.aws 11.1.0, rerunning create for an existing identifier or using modify does not change publicly_accessible. AWS's ModifyCluster API supports the change.
  • Verify the deployed setting and required client connections, and test that unapproved connections are blocked. Review authentication, least privilege and transport protection too.

Examples

These alternatives create a new single-node cluster. Set redshift_single_node_type to a type supported by both the module and AWS, and supply redshift_admin_password securely from a secret store. Prepare the actual Region, subnet and security groups too. Rerunning these tasks does not update an existing cluster's public setting.

Before

yaml
- name: Basic cluster provisioning example
  community.aws.redshift:
    command: create
    node_type: "{{ redshift_single_node_type }}"
    cluster_type: single-node
    identifier: new-cluster
    username: cluster_admin
    password: "{{ redshift_admin_password }}"
    encrypted: true
    publicly_accessible: yes

The task requests public access for a new cluster. External connectivity still depends on network paths and security groups.

After

yaml
- name: Basic cluster provisioning example
  community.aws.redshift:
    command: create
    node_type: "{{ redshift_single_node_type }}"
    cluster_type: single-node
    identifier: new-cluster
    username: cluster_admin
    password: "{{ redshift_admin_password }}"
    encrypted: true
    publicly_accessible: false

Public access is disabled for the new cluster. Verify that required clients can connect through private paths.

References