Description
publiclyAccessible: true enables public addressing for an RDS instance. Actual internet connectivity also requires suitable subnet routes, security groups, and DNS. Database authentication and permissions still apply.
A database used only by internal applications does not need a public address. Disabling public access and allowing only required application and administrative paths reduces unnecessary exposure to external connections.
Potential impact
- If internet routes and security groups allow connections from broad sources, unintended users can attempt to log in or exploit vulnerabilities. Compromised accounts or misused privileges can lead to data disclosure or modification.
- Even if security groups currently restrict access, an unnecessary public IP address leaves open the possibility of external connections after a later network-rule change.
Remediation
- Set
publiclyAccessible: falsefor internal databases. Establish the required private paths through the VPC, VPN, or another suitable connection before making the change. - Review the DB subnet group, routes, and security groups together. Inspect
pulumi previewand test that required connections still work after applying the change. - If public access is necessary, allow only approved sources and required database ports. Use database authentication, least privilege, encryption in transit, and secure password management.
Examples
These examples compare public-access settings. For deployment, specify the DB subnet group and security groups, and choose supported engine versions, instance classes, and storage. manageMasterUserPassword lets RDS manage the password in Secrets Manager. skipFinalSnapshot: true skips the final snapshot on deletion; adjust it to meet production backup and recovery requirements.
Before
name: aws-rds
runtime: yaml
description: An RDS Instance
resources:
default:
type: aws:rds:Instance
properties:
allocatedStorage: 20
dbName: mydb
engine: mysql
instanceClass: db.t3.micro
manageMasterUserPassword: true
skipFinalSnapshot: true
username: foo
publiclyAccessible: true
After
name: aws-rds
runtime: yaml
description: An RDS Instance
resources:
default:
type: aws:rds:Instance
properties:
allocatedStorage: 20
dbName: mydb
engine: mysql
instanceClass: db.t3.micro
manageMasterUserPassword: true
skipFinalSnapshot: true
username: foo
publiclyAccessible: false
Explanation: Disabling public access removes public addressing. Verify private connectivity, authentication, password management, and backups as well.