Description
Enabling PubliclyAccessible on a CloudFormation AWS::RDS::DBInstance lets the instance use a public address. Actual external connectivity depends on network settings such as subnet routing and security groups. Being able to connect does not grant data access; database authentication and permissions still apply.
A database used only by internal applications should not need a public address. When PubliclyAccessible is omitted, default behavior can depend on the VPC and DB subnet-group configuration. Set the intended access mode explicitly.
Potential impact
- An internet connection path combined with broad security-group permissions can let unintended sources attempt logins or exploit vulnerabilities. Actual data access depends on additional conditions, including authentication and permissions.
- Keeping an unnecessary public address can allow later changes to routes or security groups to open external access, even if connections are currently restricted.
Remediation
- Explicitly set
PubliclyAccessible: falsefor an internal-only instance. Prepare private connection paths for applications and management tools before turning off public access. - Review the DB subnet group's subnets and routes alongside security groups. Allow only required clients and database ports, and test that necessary connections still work after the change.
- If public access is required, restrict security groups to approved sources and use database authentication and encryption in transit. Confirm that the deployed instance's settings match the template.
Examples
These examples compare only the public-access setting; they omit the DB subnet group and security groups. Choose Engine, EngineVersion and instance-class values supported in the deployment region. SecretPassword01 is an example password: do not use it in a real deployment or store passwords directly in templates. Use a supported mechanism such as RDS password management with Secrets Manager.
Before
Resources:
MyDB:
Type: "AWS::RDS::DBInstance"
Properties:
DBInstanceIdentifier: mydbinstance
DBName: mydb
DBInstanceClass: db.m5.large
AllocatedStorage: 50
Engine: MySQL
EngineVersion: 8.0.16
MasterUsername: admin
MasterUserPassword: SecretPassword01
PubliclyAccessible: true
After
Resources:
MyDB:
Type: "AWS::RDS::DBInstance"
Properties:
DBInstanceIdentifier: mydbinstance
DBName: mydb
DBInstanceClass: db.m5.large
AllocatedStorage: 50
Engine: MySQL
EngineVersion: 8.0.16
MasterUsername: admin
MasterUserPassword: SecretPassword01
PubliclyAccessible: false
Explanation:
- Before:
PubliclyAccessible: trueenables public addressing. Actual external connectivity also depends on routing and security groups. - After:
PubliclyAccessible: falsedisables public addressing. Configure and verify the required private connections, authentication, password management and security groups separately.