Review RDS automatic minor upgrade settings

Manage RDS minor-version patches so they are not missed.

Description

When RDS AutoMinorVersionUpgrade is disabled, eligible automatic minor-version upgrades are not applied. Minor upgrades can include security patches and stability fixes. The setting defaults to true, so omitting it allows automatic upgrades.

Potential impact

Without a separate patching process, fixes for known defects can be delayed.

Remediation

Set AutoMinorVersionUpgrade: true to use automatic upgrades, and check the maintenance window and application compatibility. If upgrades are managed manually, schedule patch review and application.

Examples

These excerpts compare automatic-upgrade settings. Set MySqlEngineVersion to a supported MySQL version compatible with the application.

Before

yaml
Resources:
  MyDB:
    Type: AWS::RDS::DBInstance
    Properties:
      Engine: mysql
      EngineVersion: !Ref MySqlEngineVersion
      AutoMinorVersionUpgrade: false

After

yaml
Resources:
  MyDB:
    Type: AWS::RDS::DBInstance
    Properties:
      Engine: mysql
      EngineVersion: !Ref MySqlEngineVersion
      AutoMinorVersionUpgrade: true

References