Description
Redshift often stores analytical data for long periods, making encryption of the warehouse and snapshots important. An existing cluster that is actually unencrypted may not meet storage-protection requirements.
The current Redshift cluster creation API uses encryption by default and does not allow Encrypted: false. An omitted encryption setting should therefore not be treated as plaintext storage for a new cluster. Verify the actual state of older clusters and snapshots.
Potential impact
Unauthorized acquisition of unencrypted storage or snapshots can expose operational and sensitive data. Making a KMS key unavailable can also disrupt data access or recovery.
Remediation
- Explicitly set
encrypted = trueand check the actual cluster and snapshot state and any organizational KMS key requirement. - For an existing unencrypted cluster, review the supported encryption transition and Terraform plan. Prepare applications and processing jobs for possible write restrictions or interruption during the transition.
- Preserve required key permissions and backups, then verify data consistency, connections and recovery after the transition.
Examples
Choose a node type supported in the Region and for single-node configuration. Supply the password securely and restrict access to Terraform state. Configure networking and backup policies separately.
Request encryption disabled
resource "aws_redshift_cluster" "analytics" {
cluster_identifier = "tf-redshift-cluster"
database_name = "mydb"
master_username = "foo"
master_password = var.redshift_password
node_type = var.redshift_node_type
cluster_type = "single-node"
encrypted = false
}
This requests an unencrypted cluster, but the current creation API rejects it. It is not a valid procedure for creating a new unencrypted cluster.
Request encryption enabled
resource "aws_redshift_cluster" "analytics" {
cluster_identifier = "tf-redshift-cluster"
database_name = "mydb"
master_username = "foo"
master_password = var.redshift_password
node_type = var.redshift_node_type
cluster_type = "single-node"
encrypted = true
}
This explicitly configures encryption at rest. Before applying it to an existing cluster, check the supported transition and operational impact.