Description
Using the Redshift default port 5439 is not itself a vulnerability. A reachable service can also be identified on another port, so changing the port does not replace security groups or database authentication.
Potential impact
- Allowing clients that do not need access broadens exposure to authentication attempts and attacks.
- Changing the port without updating clients can interrupt connections.
Remediation
- Review security groups, subnets and public-access settings first, allowing only required clients. Check authentication and transport encryption too.
- If operational policy requires another port, choose one supported by the node type and update applications and administrative tools together.
Examples
These excerpts compare ports for a new cluster. Verify that the target Region and installed module support dc2.large, and supply redshift_password through a protected input that meets the password requirements. Configure networking and other operational settings separately.
Before
- name: Redshift 생성
community.aws.redshift:
command: create
node_type: dc2.large
identifier: new-cluster
username: cluster_admin
password: "{{ redshift_password }}"
port: 5439
The cluster uses default port 5439. This value alone does not determine public exposure or authentication strength.
After
- name: Redshift 생성
community.aws.redshift:
command: create
node_type: dc2.large
identifier: new-cluster
username: cluster_admin
password: "{{ redshift_password }}"
port: 1150
The cluster uses port 1150, which is allowed for DC2. Other node types can have different ranges, and a port change alone does not restrict access permissions.