Description
AWS::ElastiCache::CacheCluster declares a managed cache cluster. Cache use is not itself a vulnerability; review operational and protection settings for the engine and data purpose.
Potential impact
An unmanaged cache can leave data-access paths and failure-recovery requirements overlooked.
Remediation
Record the cache engine, owner, and connected applications, and check network access, supported encryption, and recovery options.
Examples
The second excerpt creates a new VPC cache using a supported Memcached version with TLS support, at least 1.6.12. Supply actual MemcachedEngineVersion and CacheSubnetGroup values and use TLS-capable clients. An existing cache needs a separate migration.
Before
yaml
Resources:
ElasticacheCluster:
Type: AWS::ElastiCache::CacheCluster
Properties:
Engine: memcached
CacheNodeType: cache.t2.micro
NumCacheNodes: 1
After
yaml
Resources:
ElasticacheCluster:
Type: AWS::ElastiCache::CacheCluster
Properties:
Engine: memcached
EngineVersion: !Ref MemcachedEngineVersion
CacheSubnetGroupName: !Ref CacheSubnetGroup
CacheNodeType: cache.t3.small
NumCacheNodes: 1
TransitEncryptionEnabled: true