Description
Place a Redshift cluster in an approved network and allow only required clients to connect. Missing explicit subnet-group or VPC security-group settings alone do not establish actual VPC placement or public accessibility. Omitting security groups can use the VPC’s default group.
VPC placement can still permit external access when public-access settings and security groups allow it, so review the effective configuration together.
Potential impact
Unintended routes or broad allow rules can increase database exposure. Subnets and security groups from incompatible VPCs can cause deployment or connectivity failures.
Remediation
Create a cluster subnet group from approved subnets and attach security groups from the same VPC. Review PubliclyAccessible, routing, inbound permissions and database authentication, allowing only required connections.
Examples
These excerpts show network selection only. Required creation settings such as node type, cluster type and credentials are omitted. Supply actual subnet and security-group references from the same VPC.
Before
Resources:
RedshiftCluster:
Type: AWS::Redshift::Cluster
Properties:
ClusterIdentifier: tf-redshift-cluster
DBName: mydb
Network selection is not explicit. This alone does not establish that an actual cluster is outside a VPC or publicly accessible.
After
Resources:
RedshiftSubnetGroup:
Type: AWS::Redshift::ClusterSubnetGroup
Properties:
Description: Subnet group for Redshift
SubnetIds:
- !Ref Subnet1
- !Ref Subnet2
RedshiftCluster:
Type: AWS::Redshift::Cluster
Properties:
ClusterIdentifier: tf-redshift-cluster
DBName: mydb
ClusterSubnetGroupName: !Ref RedshiftSubnetGroup
VpcSecurityGroupIds:
- !Ref RedshiftSecurityGroup
This specifies the subnet group and VPC security group. Attaching the group does not narrow its rules or disable public accessibility.