Description
The default Redshift port, 5439, is a normal service setting rather than a vulnerability by itself. Changing it does not strengthen security groups, authentication or database permissions.
If a custom port is needed, check the range supported by the node type. RA3 nodes use 5431–5455 or 8191–8215.
Potential impact
Unnecessary client access and inadequate authentication or permissions can expose or alter data regardless of the port number. Inconsistent connection settings after a port change can interrupt service.
Remediation
Limit security groups and database permissions, and use authentication and encrypted connections. If a port change is needed, select a supported value, update clients, security groups and monitoring together, and review the change set and connectivity effects.
Examples
These examples compare ports on a single-node RA3 cluster. Verify Region support and required network settings, and supply MasterUserPassword through a separate protected input.
Before
Resources:
myCluster:
Type: "AWS::Redshift::Cluster"
Properties:
PubliclyAccessible: false
DBName: "mydb"
MasterUsername: "master"
MasterUserPassword:
Ref: "MasterUserPassword"
NodeType: "ra3.large"
ClusterType: "single-node"
Port: 5439
This uses the default port 5439 and already sets PubliclyAccessible to false.
After
Resources:
myCluster:
Type: "AWS::Redshift::Cluster"
Properties:
PubliclyAccessible: false
DBName: "mydb"
MasterUsername: "master"
MasterUserPassword:
Ref: "MasterUserPassword"
NodeType: "ra3.large"
ClusterType: "single-node"
Port: 5438
This selects 5438, which RA3 supports. The change does not alter public accessibility or existing permissions.