Review Redshift VPC and subnet-group selection

Verify Redshift’s actual VPC and subnet group, and use security groups to allow only required database connections.

Description

Place a Redshift cluster in an approved network and allow only required clients to connect. Missing explicit subnet-group or VPC security-group settings alone do not establish actual VPC placement or public accessibility. Omitting security groups can use the VPC’s default group.

VPC placement can still permit external access when public-access settings and security groups allow it, so review the effective configuration together.

Potential impact

Unintended routes or broad allow rules can increase database exposure. Subnets and security groups from incompatible VPCs can cause deployment or connectivity failures.

Remediation

Create a cluster subnet group from approved subnets and attach security groups from the same VPC. Review PubliclyAccessible, routing, inbound permissions and database authentication, allowing only required connections.

Examples

These excerpts show network selection only. Required creation settings such as node type, cluster type and credentials are omitted. Supply actual subnet and security-group references from the same VPC.

Before

yaml
Resources:
  RedshiftCluster:
    Type: AWS::Redshift::Cluster
    Properties:
      ClusterIdentifier: tf-redshift-cluster
      DBName: mydb

Network selection is not explicit. This alone does not establish that an actual cluster is outside a VPC or publicly accessible.

After

yaml
Resources:
  RedshiftSubnetGroup:
    Type: AWS::Redshift::ClusterSubnetGroup
    Properties:
      Description: Subnet group for Redshift
      SubnetIds:
        - !Ref Subnet1
        - !Ref Subnet2

  RedshiftCluster:
    Type: AWS::Redshift::Cluster
    Properties:
      ClusterIdentifier: tf-redshift-cluster
      DBName: mydb
      ClusterSubnetGroupName: !Ref RedshiftSubnetGroup
      VpcSecurityGroupIds:
        - !Ref RedshiftSecurityGroup

This specifies the subnet group and VPC security group. Attaching the group does not narrow its rules or disable public accessibility.

References