Review default Redshift port use

Choose the Redshift port for operational needs, while prioritizing network restrictions, authentication and permissions.

Description

The default Redshift port, 5439, is a normal service setting rather than a vulnerability by itself. Changing it does not strengthen security groups, authentication or database permissions.

If a custom port is needed, check the range supported by the node type. RA3 nodes use 5431–5455 or 8191–8215.

Potential impact

Unnecessary client access and inadequate authentication or permissions can expose or alter data regardless of the port number. Inconsistent connection settings after a port change can interrupt service.

Remediation

Limit security groups and database permissions, and use authentication and encrypted connections. If a port change is needed, select a supported value, update clients, security groups and monitoring together, and review the change set and connectivity effects.

Examples

These examples compare ports on a single-node RA3 cluster. Verify Region support and required network settings, and supply MasterUserPassword through a separate protected input.

Before

yaml
Resources:
  myCluster:
    Type: "AWS::Redshift::Cluster"
    Properties:
      PubliclyAccessible: false
      DBName: "mydb"
      MasterUsername: "master"
      MasterUserPassword:
        Ref: "MasterUserPassword"
      NodeType: "ra3.large"
      ClusterType: "single-node"
      Port: 5439

This uses the default port 5439 and already sets PubliclyAccessible to false.

After

yaml
Resources:
  myCluster:
    Type: "AWS::Redshift::Cluster"
    Properties:
      PubliclyAccessible: false
      DBName: "mydb"
      MasterUsername: "master"
      MasterUserPassword:
        Ref: "MasterUserPassword"
      NodeType: "ra3.large"
      ClusterType: "single-node"
      Port: 5438

This selects 5438, which RA3 supports. The change does not alter public accessibility or existing permissions.

References