Review ElastiCache subnet group selection

Explicitly select the VPC and subnets for the cache.

Description

Node-based ElastiCache clusters use a subnet group to select VPC subnets. Omitting an explicit selection can use the default VPC; it does not mean that the cache is outside a VPC.

Potential impact

Unintended use of the default network can make cache access and application connectivity differ from the design.

Remediation

Set subnet_group_name to a subnet group in the intended VPC and allow only the required application access through security groups.

Examples

These Memcached examples show subnet group selection. Set the variable to the actual group name.

Before

hcl
resource "aws_elasticache_cluster" "example" {
  cluster_id           = "cluster-example"
  engine               = "memcached"
  node_type            = "cache.m4.large"
  num_cache_nodes      = 2
  parameter_group_name = aws_elasticache_parameter_group.default.id
  port                 = 11211
}

After

hcl
resource "aws_elasticache_cluster" "example" {
  cluster_id           = "cluster-example"
  engine               = "memcached"
  node_type            = "cache.m4.large"
  num_cache_nodes      = 2
  parameter_group_name = aws_elasticache_parameter_group.default.id
  port                 = 11211
  subnet_group_name    = var.subnet_group_name
}

References