Publicly accessible AWS Neptune cluster instance

Verify the need for public Neptune connectivity and restrict network and IAM permissions.

Description

A Neptune public endpoint provides an internet connection path to the graph database. Public access requires IAM authentication, while cluster security groups and network paths also limit connectivity. A public endpoint does not itself allow anonymous data access.

Potential impact

  • Unnecessary external connection attempts and exposure paths may increase.
  • Compromised IAM credentials or excessive permissions can expose or alter graph data, or disrupt service.

Remediation

  • If public connectivity is unnecessary, prepare private client connectivity before setting publicly_accessible = false on each relevant instance.
  • Allow only required clients and database ports in cluster security groups, and minimize IAM data-access permissions.
  • Review writer and reader instances and endpoints used after failover, then test that required connections work and unwanted access is blocked.

Examples

This is an instance configuration excerpt. Configure a subnet group matching the referenced cluster separately and verify that the instance class is supported by the target Region and engine. Public endpoints require Neptune 1.4.6.x or later, IAM authentication and suitable public routing.

Before

hcl
resource "aws_neptune_cluster_instance" "neptune_instance" {
  cluster_identifier  = aws_neptune_cluster.default.id
  engine              = "neptune"
  instance_class      = "db.r4.large"
  publicly_accessible = true
}

This requests public access for the instance. Cluster IAM authentication and security-group restrictions are still required.

After

hcl
resource "aws_neptune_cluster_instance" "neptune_instance" {
  cluster_identifier  = aws_neptune_cluster.default.id
  engine              = "neptune"
  instance_class      = "db.r4.large"
  publicly_accessible = false
}

This disables public access for the instance. Also verify other instances in the cluster and actual private connectivity.

References