Review Redshift default-port use

Review the Redshift port policy together with actual network access.

Description

Using the Redshift default port 5439 is not itself a vulnerability. A reachable service can also be identified on another port, so changing the port does not replace security groups or database authentication.

Potential impact

  • Allowing clients that do not need access broadens exposure to authentication attempts and attacks.
  • Changing the port without updating clients can interrupt connections.

Remediation

  • Review security groups, subnets and public-access settings first, allowing only required clients. Check authentication and transport encryption too.
  • If operational policy requires another port, choose one supported by the node type and update applications and administrative tools together.

Examples

These excerpts compare ports for a new cluster. Verify that the target Region and installed module support dc2.large, and supply redshift_password through a protected input that meets the password requirements. Configure networking and other operational settings separately.

Before

yaml
- name: Redshift 생성
  community.aws.redshift:
    command: create
    node_type: dc2.large
    identifier: new-cluster
    username: cluster_admin
    password: "{{ redshift_password }}"
    port: 5439

The cluster uses default port 5439. This value alone does not determine public exposure or authentication strength.

After

yaml
- name: Redshift 생성
  community.aws.redshift:
    command: create
    node_type: dc2.large
    identifier: new-cluster
    username: cluster_admin
    password: "{{ redshift_password }}"
    port: 1150

The cluster uses port 1150, which is allowed for DC2. Other node types can have different ranges, and a port change alone does not restrict access permissions.

References