Description
Place ElastiCache in a VPC and subnets suited to the workload, and restrict access with security groups. Omitting CacheSubnetGroupName can use a default subnet group, so omission alone does not establish placement outside a VPC or internet exposure.
Potential impact
Unintended network placement can prevent required application connections or permit access from unnecessary clients.
Remediation
Verify the subnet group’s actual VPC and subnets, then specify the approved group in CacheSubnetGroupName. Review security groups and required network paths, and check the change set for replacement and service disruption.
Examples
These historical Memcached examples compare subnet-group selection. Deployment also requires a supported node type and suitable security groups and network paths.
Before
Resources:
ElasticacheCluster:
Type: 'AWS::ElastiCache::CacheCluster'
Properties:
Engine: memcached
CacheNodeType: cache.t2.micro
NumCacheNodes: '1'
No subnet group is explicit. Verify the actual placement of the resulting cache.
After
Resources:
ElasticacheCluster:
Type: 'AWS::ElastiCache::CacheCluster'
Properties:
Engine: memcached
CacheNodeType: cache.t2.micro
NumCacheNodes: '1'
CacheSubnetGroupName: default
This selects a subnet group named default. Its name does not guarantee the intended isolation or access restrictions; review the group’s actual configuration.