Description
Node-based ElastiCache clusters use a subnet group to select VPC subnets. Omitting an explicit selection can use the default VPC; it does not mean that the cache is outside a VPC.
Potential impact
Unintended use of the default network can make cache access and application connectivity differ from the design.
Remediation
Set subnet_group_name to a subnet group in the intended VPC and allow only the required application access through security groups.
Examples
These Memcached examples show subnet group selection. Set the variable to the actual group name.
Before
hcl
resource "aws_elasticache_cluster" "example" {
cluster_id = "cluster-example"
engine = "memcached"
node_type = "cache.m4.large"
num_cache_nodes = 2
parameter_group_name = aws_elasticache_parameter_group.default.id
port = 11211
}
After
hcl
resource "aws_elasticache_cluster" "example" {
cluster_id = "cluster-example"
engine = "memcached"
node_type = "cache.m4.large"
num_cache_nodes = 2
parameter_group_name = aws_elasticache_parameter_group.default.id
port = 11211
subnet_group_name = var.subnet_group_name
}