Review the ElastiCache engine choice

Check that the cache engine and its protections meet the application’s actual requirements.

Description

Redis OSS, Valkey, and Memcached differ in features and operation. Where an organization requires particular engine capabilities or protections, the chosen engine must provide them. Not using Redis OSS does not by itself make another engine insecure or noncompliant.

Potential impact

  • Required cache features or authentication and encryption settings may be unavailable.
  • Changing engines without compatibility checks can cause client errors or data loss.

Remediation

Choose an engine for the application’s protocol, data structures, and protection requirements. Use engine = "redis" when Redis OSS is needed, with suitable networking, authentication, and backups. Other engines can also satisfy the requirements. Review resource replacement and data migration before changing engines.

Examples

These excerpts show Memcached and single-node Redis OSS configurations. Supply a supported Memcached version and configure engine-specific parameter groups and networking separately. Match the ports and clients to each configuration.

Before

hcl
resource "aws_elasticache_cluster" "example" {
  cluster_id      = "cluster-example"
  engine          = "memcached"
  node_type       = "cache.m4.large"
  num_cache_nodes = 1
  engine_version  = var.memcached_engine_version
  port            = 6379
}

After

hcl
resource "aws_elasticache_cluster" "example" {
  cluster_id      = "cluster-example"
  engine          = "redis"
  node_type       = "cache.m4.large"
  num_cache_nodes = 1
  port            = 11211
}

The second example uses Redis OSS with the required node count of 1 for this resource. Changing the engine name alone does not migrate data, provide replication, or meet every security requirement.

References