Review RDS cluster backup retention

Verify that the RDS cluster’s actual backup retention meets recovery requirements.

Description

Backup retention determines how long automated backups are kept and affects available recovery points. Production databases need an explicit recovery period appropriate for failures and operational mistakes.

Omitting retention in the Aurora example below does not disable automated backups. Aurora automated backups cannot be disabled and retain data for 1–35 days. In AWS provider v6.14.0, aws_rds_cluster.backup_retention_period defaults to one day.

Potential impact

  • Unclear recovery planning: it can be difficult to determine whether the required recovery point remains available.
  • Data loss risk: a retention period shorter than required can leave needed recovery data unavailable.
  • Operational inconsistency: different backup standards across environments complicate reviews and audits.

Remediation

  • Set backup_retention_period explicitly to meet recovery requirements.
  • Define retention standards based on service criticality and apply them consistently.
  • Check actual restorable times and include regular restore tests in operational procedures.

Examples

These are Aurora cluster excerpts. Configure instances and networking separately, and use matching Regions and Availability Zones. Supply an engine-compliant password securely through var.db_password and protect Terraform state, which can contain the password.

Use default retention

hcl
resource "aws_rds_cluster" "example" {
  cluster_identifier      = "aurora-cluster-demo"
  engine                  = "aurora-postgresql"
  availability_zones      = ["us-west-2a", "us-west-2b", "us-west-2c"]
  database_name           = "mydb"
  master_username         = "foo"
  master_password         = var.db_password
  preferred_backup_window = "07:00-09:00"
}

Specify retention

hcl
resource "aws_rds_cluster" "example" {
  cluster_identifier      = "aurora-cluster-demo"
  engine                  = "aurora-postgresql"
  availability_zones      = ["us-west-2a", "us-west-2b", "us-west-2c"]
  database_name           = "mydb"
  master_username         = "foo"
  master_password         = var.db_password
  backup_retention_period = 5
  preferred_backup_window = "07:00-09:00"
}

The first example uses the provider’s default retention. The second explicitly specifies five days. Five days is not appropriate for every service; choose the period based on business recovery requirements.

References