Description
Setting backup_retention_period = 0 disables automated backups for an RDS DB instance. The aws_db_instance resource in AWS provider v6.14.0 also defaults to zero. Automated backups provide important point-in-time recovery protection after failures, operational mistakes, or data corruption.
Manual snapshots can be managed separately, but do not provide the same recovery points as automated backups. Explicitly choose the automated backup period required by a production database.
Potential impact
- Recovery gaps: the database may not be restorable to the desired point after a failure or deletion.
- Greater data loss: recent changes can be lost if no other recovery mechanism is available.
- Inconsistent operations: differing backup policies make instances harder to manage.
Remediation
- Set
backup_retention_periodto 1–35 days according to recovery requirements. - Plan the change window: moving between zero and a nonzero retention period causes an outage.
- Include required snapshot retention and restore tests alongside automated backups in operational procedures.
Examples
These excerpts compare backup settings. MySQL 5.7 and db.t2.micro are retained from the earlier example; verify support in the actual Region and environment. Configure networking separately and securely supply a valid password through var.db_password. Protect Terraform state, which can store that password.
Before
resource "aws_db_instance" "example" {
allocated_storage = 20
storage_type = "gp2"
engine = "mysql"
engine_version = "5.7"
instance_class = "db.t2.micro"
db_name = "mydb"
username = "foo"
password = var.db_password
backup_retention_period = 0
}
After
resource "aws_db_instance" "example" {
allocated_storage = 20
storage_type = "gp2"
engine = "mysql"
engine_version = "5.7"
instance_class = "db.t2.micro"
db_name = "mydb"
username = "foo"
password = var.db_password
backup_retention_period = 12
}
Before the change, automated backups are disabled. Afterward, retention is set to twelve days. This period is illustrative; verify actual backup completion and restore capability.