Description
A DMS replication instance connects to the source and target databases to migrate data. publiclyAccessible controls public addressing for this instance; it does not directly make either database public. Actual connectivity depends on subnet routing, security groups, and the destination's access rules.
If the property is omitted, check the Pulumi provider and deployment state instead of assuming either public or private addressing. Set publiclyAccessible: false when private connectivity is required. A public address alone does not disclose migration settings or credentials; IAM controls DMS administrative access.
Potential impact
- An unnecessary public IP address combined with broad security-group permissions or routing can increase the replication instance's exposure to external networks.
- Moving to a private configuration without planning connectivity can interrupt replication if the source or target becomes unreachable.
Remediation
- Set
publiclyAccessible: falseand provide the required source and target paths through VPC connectivity, peering, VPN, Direct Connect, or another suitable connection. Restrict security groups and destination allow-lists to required addresses and ports, and provide appropriate outbound connectivity for internet destinations. - Changing this setting on an existing DMS instance requires replacement. Inspect
pulumi previewfor replacement and dependent-resource changes, and plan the move with identifier conflicts and downtime in mind. - Review replication tasks, endpoints, and task-movement requirements before the move. Test both endpoint connections, replication resumption, and data consistency on the new instance. Prepare recovery procedures before removing the old resources.
Examples
These partial examples compare the public-access values. Configure the subnet group, endpoints, IAM permissions, and network paths separately, and replace sg-12345678 with a real security-group ID. Select an instance class and engine version supported in your Region and suitable for the replication workload.
Before
name: aws-dms
runtime: yaml
description: amazon dms replication instance
resources:
test:
type: aws:dms:ReplicationInstance
properties:
allocatedStorage: 20
multiAz: false
publiclyAccessible: true
replicationInstanceClass: dms.t3.micro
replicationInstanceId: test-dms-replication-instance-tf
vpcSecurityGroupIds:
- sg-12345678
After
name: aws-dms
runtime: yaml
description: amazon dms replication instance
resources:
test:
type: aws:dms:ReplicationInstance
properties:
allocatedStorage: 20
multiAz: false
publiclyAccessible: false
replicationInstanceClass: dms.t3.micro
replicationInstanceId: test-dms-replication-instance-tf
vpcSecurityGroupIds:
- sg-12345678
Explanation:
- Before: Public addressing is enabled for the replication instance. Actual connectivity also depends on the network configuration.
- After: Private addressing is requested. Applying this change to an existing instance requires planning its replacement and the migration of replication tasks.