Review Redshift encryption at rest

Check actual Redshift encryption and transition requirements for existing clusters.

Description

Redshift often stores analytical data for long periods, making encryption of the warehouse and snapshots important. An existing cluster that is actually unencrypted may not meet storage-protection requirements.

The current Redshift cluster creation API uses encryption by default and does not allow Encrypted: false. An omitted encryption setting should therefore not be treated as plaintext storage for a new cluster. Verify the actual state of older clusters and snapshots.

Potential impact

Unauthorized acquisition of unencrypted storage or snapshots can expose operational and sensitive data. Making a KMS key unavailable can also disrupt data access or recovery.

Remediation

  • Explicitly set encrypted = true and check the actual cluster and snapshot state and any organizational KMS key requirement.
  • For an existing unencrypted cluster, review the supported encryption transition and Terraform plan. Prepare applications and processing jobs for possible write restrictions or interruption during the transition.
  • Preserve required key permissions and backups, then verify data consistency, connections and recovery after the transition.

Examples

Choose a node type supported in the Region and for single-node configuration. Supply the password securely and restrict access to Terraform state. Configure networking and backup policies separately.

Request encryption disabled

hcl
resource "aws_redshift_cluster" "analytics" {
  cluster_identifier = "tf-redshift-cluster"
  database_name      = "mydb"
  master_username    = "foo"
  master_password    = var.redshift_password
  node_type          = var.redshift_node_type
  cluster_type       = "single-node"
  encrypted          = false
}

This requests an unencrypted cluster, but the current creation API rejects it. It is not a valid procedure for creating a new unencrypted cluster.

Request encryption enabled

hcl
resource "aws_redshift_cluster" "analytics" {
  cluster_identifier = "tf-redshift-cluster"
  database_name      = "mydb"
  master_username    = "foo"
  master_password    = var.redshift_password
  node_type          = var.redshift_node_type
  cluster_type       = "single-node"
  encrypted          = true
}

This explicitly configures encryption at rest. Before applying it to an existing cluster, check the supported transition and operational impact.

References