Review Redshift cluster network selection

Specify the Redshift cluster subnet group and security groups.

Description

A provisioned Redshift cluster’s subnet group determines its VPC and subnets. If security groups are not specified, the default VPC security group may be used, so verify the actual permitted connections.

Potential impact

Relying on network defaults can leave access paths and permitted senders different from operational intent.

Remediation

Specify cluster_subnet_group_name and vpc_security_group_ids from the same VPC. Also check public accessibility, routing, and allowed traffic.

Examples

The examples show explicit network selection. VPC placement alone does not guarantee private access. The password is illustrative and needs separate management in a real deployment.

Before

hcl
resource "aws_redshift_cluster" "example" {
  cluster_identifier = "tf-redshift-cluster"
  database_name      = "mydb"
  master_username    = "foo"
  master_password    = "Mustbe8characters"
  node_type          = "dc2.large"
  cluster_type       = "single-node"
}

After

hcl
resource "aws_redshift_cluster" "example" {
  cluster_identifier       = "tf-redshift-cluster"
  database_name            = "mydb"
  master_username          = "foo"
  master_password          = "Mustbe8characters"
  node_type                = "dc2.large"
  cluster_type             = "single-node"
  vpc_security_group_ids   = [aws_security_group.redshift.id]
  cluster_subnet_group_name = aws_redshift_subnet_group.redshift_subnet_group.id
}

References