Review ElastiCache VPC and subnet-group selection

Verify the actual ElastiCache subnet group and VPC, and permit connections only from required clients.

Description

Place ElastiCache in a VPC and subnets suited to the workload, and restrict access with security groups. Omitting CacheSubnetGroupName can use a default subnet group, so omission alone does not establish placement outside a VPC or internet exposure.

Potential impact

Unintended network placement can prevent required application connections or permit access from unnecessary clients.

Remediation

Verify the subnet group’s actual VPC and subnets, then specify the approved group in CacheSubnetGroupName. Review security groups and required network paths, and check the change set for replacement and service disruption.

Examples

These historical Memcached examples compare subnet-group selection. Deployment also requires a supported node type and suitable security groups and network paths.

Before

yaml
Resources:
  ElasticacheCluster:
    Type: 'AWS::ElastiCache::CacheCluster'
    Properties:    
      Engine: memcached
      CacheNodeType: cache.t2.micro
      NumCacheNodes: '1'

No subnet group is explicit. Verify the actual placement of the resulting cache.

After

yaml
Resources:
  ElasticacheCluster:
    Type: 'AWS::ElastiCache::CacheCluster'
    Properties:    
      Engine: memcached
      CacheNodeType: cache.t2.micro
      NumCacheNodes: '1'
      CacheSubnetGroupName: default

This selects a subnet group named default. Its name does not guarantee the intended isolation or access restrictions; review the group’s actual configuration.

References