Insufficient RDS backup retention

Retain backups long enough to detect problems and recover.

Description

With short RDS backup retention, the required recovery point may already be outside the retention window when corruption is discovered late. Seven days is an example operational baseline, not the service’s minimum allowed value.

Potential impact

Expired backups can prevent recovery to the state before corruption or require data reconstruction.

Remediation

Set BackupRetentionPeriod according to detection time, recovery objectives, and retention policy. If the baseline is at least seven days, configure that or longer and verify restoration.

Examples

These excerpts increase an Aurora MySQL cluster’s retention from 3 to 16 days. Sixteen days is not suitable for every environment.

Before

yaml
Resources:
  DatabaseCluster:
    Type: "AWS::RDS::DBCluster"
    Properties:
      Engine: aurora-mysql
      StorageEncrypted: true
      BackupRetentionPeriod: 3
      PreferredBackupWindow: '12:00-13:00'

After

yaml
Resources:
  DatabaseCluster:
    Type: "AWS::RDS::DBCluster"
    Properties:
      Engine: aurora-mysql
      StorageEncrypted: true
      BackupRetentionPeriod: 16
      PreferredBackupWindow: '12:00-13:00'

References