Description
A provisioned Redshift cluster’s subnet group determines its VPC and subnets. If security groups are not specified, the default VPC security group may be used, so verify the actual permitted connections.
Potential impact
Relying on network defaults can leave access paths and permitted senders different from operational intent.
Remediation
Specify cluster_subnet_group_name and vpc_security_group_ids from the same VPC. Also check public accessibility, routing, and allowed traffic.
Examples
The examples show explicit network selection. VPC placement alone does not guarantee private access. The password is illustrative and needs separate management in a real deployment.
Before
hcl
resource "aws_redshift_cluster" "example" {
cluster_identifier = "tf-redshift-cluster"
database_name = "mydb"
master_username = "foo"
master_password = "Mustbe8characters"
node_type = "dc2.large"
cluster_type = "single-node"
}
After
hcl
resource "aws_redshift_cluster" "example" {
cluster_identifier = "tf-redshift-cluster"
database_name = "mydb"
master_username = "foo"
master_password = "Mustbe8characters"
node_type = "dc2.large"
cluster_type = "single-node"
vpc_security_group_ids = [aws_security_group.redshift.id]
cluster_subnet_group_name = aws_redshift_subnet_group.redshift_subnet_group.id
}