RDS instance automated backups disabled

Set a positive automated backup retention period that meets the RDS instance’s recovery requirements.

Description

Setting backup_retention_period = 0 disables automated backups for an RDS DB instance. The aws_db_instance resource in AWS provider v6.14.0 also defaults to zero. Automated backups provide important point-in-time recovery protection after failures, operational mistakes, or data corruption.

Manual snapshots can be managed separately, but do not provide the same recovery points as automated backups. Explicitly choose the automated backup period required by a production database.

Potential impact

  • Recovery gaps: the database may not be restorable to the desired point after a failure or deletion.
  • Greater data loss: recent changes can be lost if no other recovery mechanism is available.
  • Inconsistent operations: differing backup policies make instances harder to manage.

Remediation

  • Set backup_retention_period to 1–35 days according to recovery requirements.
  • Plan the change window: moving between zero and a nonzero retention period causes an outage.
  • Include required snapshot retention and restore tests alongside automated backups in operational procedures.

Examples

These excerpts compare backup settings. MySQL 5.7 and db.t2.micro are retained from the earlier example; verify support in the actual Region and environment. Configure networking separately and securely supply a valid password through var.db_password. Protect Terraform state, which can store that password.

Before

hcl
resource "aws_db_instance" "example" {
  allocated_storage       = 20
  storage_type            = "gp2"
  engine                  = "mysql"
  engine_version          = "5.7"
  instance_class          = "db.t2.micro"
  db_name                 = "mydb"
  username                = "foo"
  password                = var.db_password
  backup_retention_period = 0
}

After

hcl
resource "aws_db_instance" "example" {
  allocated_storage       = 20
  storage_type            = "gp2"
  engine                  = "mysql"
  engine_version          = "5.7"
  instance_class          = "db.t2.micro"
  db_name                 = "mydb"
  username                = "foo"
  password                = var.db_password
  backup_retention_period = 12
}

Before the change, automated backups are disabled. Afterward, retention is set to twelve days. This period is illustrative; verify actual backup completion and restore capability.

References