RDS instance enables public access

A public address can provide an external connection path to an RDS instance. Define the required access scope and manage public accessibility together with network permissions.

Description

Enabling PubliclyAccessible on a CloudFormation AWS::RDS::DBInstance lets the instance use a public address. Actual external connectivity depends on network settings such as subnet routing and security groups. Being able to connect does not grant data access; database authentication and permissions still apply.

A database used only by internal applications should not need a public address. When PubliclyAccessible is omitted, default behavior can depend on the VPC and DB subnet-group configuration. Set the intended access mode explicitly.

Potential impact

  • An internet connection path combined with broad security-group permissions can let unintended sources attempt logins or exploit vulnerabilities. Actual data access depends on additional conditions, including authentication and permissions.
  • Keeping an unnecessary public address can allow later changes to routes or security groups to open external access, even if connections are currently restricted.

Remediation

  • Explicitly set PubliclyAccessible: false for an internal-only instance. Prepare private connection paths for applications and management tools before turning off public access.
  • Review the DB subnet group's subnets and routes alongside security groups. Allow only required clients and database ports, and test that necessary connections still work after the change.
  • If public access is required, restrict security groups to approved sources and use database authentication and encryption in transit. Confirm that the deployed instance's settings match the template.

Examples

These examples compare only the public-access setting; they omit the DB subnet group and security groups. Choose Engine, EngineVersion and instance-class values supported in the deployment region. SecretPassword01 is an example password: do not use it in a real deployment or store passwords directly in templates. Use a supported mechanism such as RDS password management with Secrets Manager.

Before

yaml
Resources:
  MyDB:
    Type: "AWS::RDS::DBInstance"
    Properties:
      DBInstanceIdentifier: mydbinstance
      DBName: mydb
      DBInstanceClass: db.m5.large
      AllocatedStorage: 50
      Engine: MySQL
      EngineVersion: 8.0.16
      MasterUsername: admin
      MasterUserPassword: SecretPassword01
      PubliclyAccessible: true

After

yaml
Resources:
  MyDB:
    Type: "AWS::RDS::DBInstance"
    Properties:
      DBInstanceIdentifier: mydbinstance
      DBName: mydb
      DBInstanceClass: db.m5.large
      AllocatedStorage: 50
      Engine: MySQL
      EngineVersion: 8.0.16
      MasterUsername: admin
      MasterUserPassword: SecretPassword01
      PubliclyAccessible: false

Explanation:

  • Before: PubliclyAccessible: true enables public addressing. Actual external connectivity also depends on routing and security groups.
  • After: PubliclyAccessible: false disables public addressing. Configure and verify the required private connections, authentication, password management and security groups separately.

References