Description
Redshift's PubliclyAccessible: true configures the cluster for connections from a public network. Actual connectivity depends on subnets, routes and security groups; database authentication and permissions still apply. This property's default is false.
Use private connectivity for analytics environments that do not require public connections.
Potential impact
- A reachable database can face unwanted login and exploitation attempts.
- Compromised credentials or excessive data permissions can combine with exposure to cause data disclosure, modification or service interruption.
Remediation
- Prepare private network and DNS paths for clients and analytics tools before setting
PubliclyAccessible: false. - Limit security groups to actual clients and database ports, and review subnets and routing. Minimize allowed sources even when public connectivity is necessary.
- Verify required queries and jobs after the change, and check TLS, authentication and least privilege separately.
Examples
These compare public settings on the same cluster. Supply a node type supporting single-node operation in the Region, an actual cluster subnet group and VPC security groups. Redshift manages the admin password in Secrets Manager. Review the change set and client cutover before applying changes to an existing cluster.
Before
Parameters:
NodeType:
Type: String
ClusterSubnetGroupName:
Type: String
VpcSecurityGroupIds:
Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
myCluster:
Type: AWS::Redshift::Cluster
Properties:
PubliclyAccessible: true
DBName: mydb
MasterUsername: master
ManageMasterPassword: true
NodeType: !Ref NodeType
ClusterType: single-node
ClusterSubnetGroupName: !Ref ClusterSubnetGroupName
VpcSecurityGroupIds: !Ref VpcSecurityGroupIds
This enables public access; it does not grant every source permission to read data. Check actual network rules, authentication and permissions.
After
Parameters:
NodeType:
Type: String
ClusterSubnetGroupName:
Type: String
VpcSecurityGroupIds:
Type: List<AWS::EC2::SecurityGroup::Id>
Resources:
myCluster:
Type: AWS::Redshift::Cluster
Properties:
PubliclyAccessible: false
DBName: mydb
MasterUsername: master
ManageMasterPassword: true
NodeType: !Ref NodeType
ClusterType: single-node
ClusterSubnetGroupName: !Ref ClusterSubnetGroupName
VpcSecurityGroupIds: !Ref VpcSecurityGroupIds
This disables public access. Required clients need private connectivity, and data permissions must still be restricted separately.