RDS deletion protection disabled

Enable deletion protection for databases that must be retained.

Description

When RDS DeletionProtection is disabled, this safeguard does not block an authorized deletion request. When enabled, deletion protection must explicitly be turned off before the instance can be deleted.

Potential impact

Accidental deletion can interrupt service and require backup restoration or connection changes.

Remediation

Set DeletionProtection: true for instances that must be retained. Prepare the necessary recovery procedures as well, because deletion protection does not replace backups.

Examples

These replica-definition excerpts compare only deletion protection. Prepare the source database and remaining replication settings separately.

Before

yaml
Resources:
  MyDBSmall:
    Type: "AWS::RDS::DBInstance"
    Properties:
      DBInstanceClass: db.t3.small
      SourceDBInstanceIdentifier: db-source
      SourceRegion: ap-northeast-2
      DeletionProtection: false

After

yaml
Resources:
  MyDBSmall:
    Type: "AWS::RDS::DBInstance"
    Properties:
      DBInstanceClass: db.t3.small
      SourceDBInstanceIdentifier: db-source
      SourceRegion: ap-northeast-2
      DeletionProtection: true

References