Redshift public-access settings need review

Review the need for public Redshift access, and use prepared private connectivity for internal analytics.

Description

Redshift's PubliclyAccessible: true configures the cluster for connections from a public network. Actual connectivity depends on subnets, routes and security groups; database authentication and permissions still apply. This property's default is false.

Use private connectivity for analytics environments that do not require public connections.

Potential impact

  • A reachable database can face unwanted login and exploitation attempts.
  • Compromised credentials or excessive data permissions can combine with exposure to cause data disclosure, modification or service interruption.

Remediation

  • Prepare private network and DNS paths for clients and analytics tools before setting PubliclyAccessible: false.
  • Limit security groups to actual clients and database ports, and review subnets and routing. Minimize allowed sources even when public connectivity is necessary.
  • Verify required queries and jobs after the change, and check TLS, authentication and least privilege separately.

Examples

These compare public settings on the same cluster. Supply a node type supporting single-node operation in the Region, an actual cluster subnet group and VPC security groups. Redshift manages the admin password in Secrets Manager. Review the change set and client cutover before applying changes to an existing cluster.

Before

yaml
Parameters:
  NodeType:
    Type: String
  ClusterSubnetGroupName:
    Type: String
  VpcSecurityGroupIds:
    Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
  myCluster:
    Type: AWS::Redshift::Cluster
    Properties:
      PubliclyAccessible: true
      DBName: mydb
      MasterUsername: master
      ManageMasterPassword: true
      NodeType: !Ref NodeType
      ClusterType: single-node
      ClusterSubnetGroupName: !Ref ClusterSubnetGroupName
      VpcSecurityGroupIds: !Ref VpcSecurityGroupIds

This enables public access; it does not grant every source permission to read data. Check actual network rules, authentication and permissions.

After

yaml
Parameters:
  NodeType:
    Type: String
  ClusterSubnetGroupName:
    Type: String
  VpcSecurityGroupIds:
    Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
  myCluster:
    Type: AWS::Redshift::Cluster
    Properties:
      PubliclyAccessible: false
      DBName: mydb
      MasterUsername: master
      ManageMasterPassword: true
      NodeType: !Ref NodeType
      ClusterType: single-node
      ClusterSubnetGroupName: !Ref ClusterSubnetGroupName
      VpcSecurityGroupIds: !Ref VpcSecurityGroupIds

This disables public access. Required clients need private connectivity, and data permissions must still be restricted separately.

References