Description
Redshift is a data warehouse that can store large volumes of business data, logs and aggregated information. Encryption at rest protects these data and snapshots.
The current Redshift API encrypts new clusters by default and rejects an explicit Encrypted: false request. An omitted template option does not establish unencrypted storage. Check actual encryption and keys, including on older clusters.
Potential impact
Unauthorized acquisition of actually unencrypted storage or snapshots can expose analytical data and sensitive information. Database permissions and network restrictions remain necessary even with encryption enabled.
Remediation
- Explicitly request
Encrypted: truefor new clusters and choose a KMS key that meets organizational requirements. - Use a supported encryption conversion for existing unencrypted clusters. Preserve backups and plan for read-only operation and other operational effects during conversion.
- Verify actual encryption and normal data access afterward, and retain required key permissions.
Examples
These are creation excerpts. Define the referenced values in the full template, supply a securely managed password, and choose a node type supported for single-node deployment in the Region. Review the retained public-access setting and networking separately.
Encryption option omitted
Resources:
RedshiftCluster:
Type: AWS::Redshift::Cluster
Properties:
DBName: !Sub ${DatabaseName}
MasterUserPassword: !Ref MasterUserPassword
MasterUsername: !Ref MasterUsername
PubliclyAccessible: true
ClusterType: single-node
NodeType: !Ref RedshiftNodeType
Port: 5439
Current creation defaults provide encryption. This omission alone does not mean plaintext storage.
Explicit encryption requirement
Resources:
RedshiftCluster:
Type: AWS::Redshift::Cluster
Properties:
DBName: !Sub ${DatabaseName}
MasterUserPassword: !Ref MasterUserPassword
MasterUsername: !Ref MasterUsername
PubliclyAccessible: true
ClusterType: single-node
NodeType: !Ref RedshiftNodeType
Port: 5439
Encrypted: true
This states the encryption requirement. Before modifying an existing cluster, verify its actual state and the supported conversion procedure.