RDS automated backups are disabled

Set RDS automated backup retention to meet recovery objectives and test actual restores.

Description

Setting BackupRetentionPeriod to 0 disables automated backups for an RDS DB instance. Point-in-time recovery based on those backups is unavailable, but this does not mean that separately created manual snapshots do not exist.

Potential impact

After data corruption or deletion, the required recovery point may be unavailable, increasing data loss or service downtime.

Remediation

For DB instances that need automated backups, choose a retention period of 1–35 days based on recovery objectives. Plan for an outage when changing between 0 and a positive value. Check backup status and available recovery points, and regularly test restoration.

Examples

These Oracle DB instance excerpts require compatible DBAllocatedStorage, DBInstanceType, licensing and network settings. The master password uses RDS-managed credentials.

Before

yaml
Resources:
  MyDB:
    Type: AWS::RDS::DBInstance
    Properties:
      AllocatedStorage: !Ref DBAllocatedStorage
      DBInstanceClass: !Ref DBInstanceType
      Engine: oracle-ee
      MasterUsername: master
      ManageMasterUserPassword: true
      BackupRetentionPeriod: 0

Automated backups are disabled. Assess whether separate snapshots can meet the required recovery point.

After

yaml
Resources:
  MyDB:
    Type: AWS::RDS::DBInstance
    Properties:
      AllocatedStorage: !Ref DBAllocatedStorage
      DBInstanceClass: !Ref DBInstanceType
      Engine: oracle-ee
      MasterUsername: master
      ManageMasterUserPassword: true
      BackupRetentionPeriod: 7

Automated backups are retained for 7 days. This is an example period; adjust it to the workload’s recovery objectives.

References