RDS instance may receive a public IP address

Disable public access for internal RDS instances and configure private connectivity and security groups to reduce unnecessary external access.

Description

Enabling RDS public access can give an instance a public IP address. Internet connections also require suitable subnet routing and security-group permissions, while database authentication and privileges apply separately. Check whether an internal database needs a public address at all.

When publiclyAccessible is omitted, Crossplane AWS provider v0.17.0 leaves it unspecified in the AWS request; the default depends on the VPC and DB subnet group. Explicitly set publiclyAccessible: false for internal instances instead of relying on that default.

Potential impact

  • If an internet path reaches a publicly addressed database and security groups allow broad access, unintended sources can attempt to log in or exploit vulnerabilities. Actual data access also depends on authentication, permissions, and other conditions.
  • An unintended public address combined with broad network permissions can increase the database's exposure to external clients.

Remediation

  • Set publiclyAccessible: false for internal instances.
  • Check the actual subnets and route tables associated with the DBSubnetGroup, and restrict security groups to required sources and database ports. An internet gateway in the VPC alone does not establish whether an individual subnet is public.
  • Establish the private connections that applications and administrators need before disabling public access, and test connectivity after the change. If the workload requires public access, restrict security groups to approved sources and database ports, and use authentication and encryption in transit.

Examples

These partial examples use Crossplane AWS v0.17.0 resource formats. Add required properties such as the engine and instance class, and replace the subnet IDs and DB subnet group name with values for your environment. Configure routing and security groups separately.

Before

yaml
apiVersion: database.aws.crossplane.io/v1beta1
kind: RDSInstance
metadata:
  name: sample-cluster3
spec:
  forProvider:
    publiclyAccessible: true
    dbSubnetGroupName: my-db-subnet-group

---

apiVersion: database.aws.crossplane.io/v1beta1
kind: DBSubnetGroup
metadata:
  name: my-db-subnet-group
spec:
  forProvider:
    description: "My DB Subnet Group"
    subnetIds:
      - subnet-12345678
      - subnet-87654321

After

yaml
apiVersion: database.aws.crossplane.io/v1beta1
kind: RDSInstance
metadata:
  name: sample-cluster3
spec:
  forProvider:
    publiclyAccessible: false
    dbSubnetGroupName: my-db-subnet-group

---

apiVersion: database.aws.crossplane.io/v1beta1
kind: DBSubnetGroup
metadata:
  name: my-db-subnet-group
spec:
  forProvider:
    description: "My DB Subnet Group"
    subnetIds:
      - subnet-12345678
      - subnet-87654321

Explanation:

  • Before: Public access is enabled. Actual internet connectivity also depends on the network configuration.
  • After: The instance is requested without a public IP address. Configure the necessary private connectivity, authentication, and security groups, then test connections.

References