Description
publicly_accessible = true enables public addressing for a DMS replication instance. Actual communication depends on subnet routes, security groups, and the destinations' access rules. This setting does not directly publish the source or target database or grant access to migration settings and credentials.
Explicitly disable public access for instances that need only private connectivity. Removing the property does not guarantee a private configuration; check terraform plan and the deployed instance settings.
Potential impact
- An unnecessary public IP address combined with broad network permissions can create unintended external communication paths.
- Changing public access without planning connectivity and instance replacement can interrupt source or target connections and replication.
Remediation
- Set
publicly_accessible = falseand establish the required source and target paths through the VPC, peering, VPN, Direct Connect, or another suitable connection. Restrict security groups and destination allow-lists to necessary addresses and ports. Configure an appropriate outbound path if an internet destination is required. - Changing public access on an existing instance requires replacement. Inspect
terraform planfor replacement and dependent-resource changes, and plan for identifier conflicts, task stopping, movement and resumption, and recovery. Do not delete old resources before verifying the new instance's connections. - Check the provider reference and task-movement requirements. After applying the change, verify both endpoint connections, replication status, and data consistency.
Examples
These are partial configurations. Define the referenced subnet group and IAM policy attachments separately, and replace the security-group ID and KMS key ARN with values for your environment. Use matching Regions for the provider, subnets, and KMS key, and choose an engine version and capacity suitable for the workload.
Before
resource "aws_dms_replication_instance" "test" {
allocated_storage = 20
apply_immediately = true
auto_minor_version_upgrade = true
kms_key_arn = "arn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012"
multi_az = false
preferred_maintenance_window = "sun:10:30-sun:14:30"
publicly_accessible = true
replication_instance_class = "dms.t3.micro"
replication_instance_id = "test-dms-replication-instance-tf"
replication_subnet_group_id = aws_dms_replication_subnet_group.test-dms-replication-subnet-group-tf.id
vpc_security_group_ids = [
"sg-12345678",
]
depends_on = [
aws_iam_role_policy_attachment.dms-access-for-endpoint-AmazonDMSRedshiftS3Role,
aws_iam_role_policy_attachment.dms-cloudwatch-logs-role-AmazonDMSCloudWatchLogsRole,
aws_iam_role_policy_attachment.dms-vpc-role-AmazonDMSVPCManagementRole
]
}
After
resource "aws_dms_replication_instance" "test" {
allocated_storage = 20
apply_immediately = true
auto_minor_version_upgrade = true
kms_key_arn = "arn:aws:kms:us-east-1:123456789012:key/12345678-1234-1234-1234-123456789012"
multi_az = false
preferred_maintenance_window = "sun:10:30-sun:14:30"
publicly_accessible = false
replication_instance_class = "dms.t3.micro"
replication_instance_id = "test-dms-replication-instance-tf"
replication_subnet_group_id = aws_dms_replication_subnet_group.test-dms-replication-subnet-group-tf.id
vpc_security_group_ids = [
"sg-12345678",
]
depends_on = [
aws_iam_role_policy_attachment.dms-access-for-endpoint-AmazonDMSRedshiftS3Role,
aws_iam_role_policy_attachment.dms-cloudwatch-logs-role-AmazonDMSCloudWatchLogsRole,
aws_iam_role_policy_attachment.dms-vpc-role-AmazonDMSVPCManagementRole
]
}
Explanation: The updated configuration explicitly disables public access. After replacement, the instance must still be able to reach both endpoints through the required private paths.