Amazon ElastiCache cache inventory

Include cache engines and data flows in the asset inventory.

Description

AWS::ElastiCache::CacheCluster declares a managed cache cluster. Cache use is not itself a vulnerability; review operational and protection settings for the engine and data purpose.

Potential impact

An unmanaged cache can leave data-access paths and failure-recovery requirements overlooked.

Remediation

Record the cache engine, owner, and connected applications, and check network access, supported encryption, and recovery options.

Examples

The second excerpt creates a new VPC cache using a supported Memcached version with TLS support, at least 1.6.12. Supply actual MemcachedEngineVersion and CacheSubnetGroup values and use TLS-capable clients. An existing cache needs a separate migration.

Before

yaml
Resources:
  ElasticacheCluster:
    Type: AWS::ElastiCache::CacheCluster
    Properties:
      Engine: memcached
      CacheNodeType: cache.t2.micro
      NumCacheNodes: 1

After

yaml
Resources:
  ElasticacheCluster:
    Type: AWS::ElastiCache::CacheCluster
    Properties:
      Engine: memcached
      EngineVersion: !Ref MemcachedEngineVersion
      CacheSubnetGroupName: !Ref CacheSubnetGroup
      CacheNodeType: cache.t3.small
      NumCacheNodes: 1
      TransitEncryptionEnabled: true

References