RDS automatic minor upgrades are disabled

Maintain a separate patch plan when automatic minor upgrades are disabled.

Description

Setting auto_minor_version_upgrade = false disables ordinary RDS automatic minor upgrades. Bug fixes and security patches can be delayed without a managed manual-update process. RDS can still apply minor upgrades for critical security issues or end of support regardless of this setting.

Potential impact

  • Security fixes and reliability improvements may be delayed.
  • Operators must track engine versions and update schedules themselves.

Remediation

Set auto_minor_version_upgrade = true where it fits the operational policy, and review the maintenance window and compatibility. Automatic upgrades do not always select the latest release. If managing updates manually, maintain a patch schedule, backups, and post-upgrade validation.

Examples

These excerpts compare only the automatic-upgrade option. Supply a MySQL version and instance class supported in the Region, and configure storage and credentials separately.

Before

hcl
resource "aws_db_instance" "example" {
  engine                     = "mysql"
  engine_version             = var.mysql_engine_version
  instance_class             = var.db_instance_class
  auto_minor_version_upgrade = false
}

After

hcl
resource "aws_db_instance" "example" {
  engine                     = "mysql"
  engine_version             = var.mysql_engine_version
  instance_class             = var.db_instance_class
  auto_minor_version_upgrade = true
}

The revision permits automatic installation of the minor-upgrade target designated by RDS. Upgrades can cause downtime, so plan maintenance accordingly.

References