AWS Redshift cluster public-access settings need review

Allow public analytical-database connectivity only when it is needed.

Description

A Redshift cluster with public access enabled can accept internet connections when network conditions permit. Actual reachability depends on security groups and routing, while database authentication and permissions govern data access. Review both the public-access setting and the clients actually allowed to connect.

Potential impact

  • Unnecessary external connections and password-guessing attempts may increase.
  • Compromise of a vulnerable account or service can expose analytical data or interrupt business operations.

Remediation

  • If public connectivity is unnecessary, explicitly set publicly_accessible = false. Prepare private application and administrator connectivity before changing it.
  • Review subnets, routing and security groups together, allowing only required clients and database ports.
  • Assess change impact and verify required connections and rejection of unwanted access at the actual endpoint. Maintain database authentication, permissions and transport encryption.

Examples

This is a cluster creation excerpt. Supply a redshift_node_type supported in the target Region for a single-node cluster. Supply the password securely, protect Terraform state, and configure networking and backups separately.

Before

hcl
resource "aws_redshift_cluster" "analytics" {
  cluster_identifier   = "tf-redshift-cluster"
  database_name        = "mydb"
  master_username      = "foo"
  master_password      = var.redshift_password
  node_type            = var.redshift_node_type
  cluster_type         = "single-node"
  publicly_accessible  = true
}

This enables public access. Actual internet connectivity also depends on routing and security-group permissions.

After

hcl
resource "aws_redshift_cluster" "analytics" {
  cluster_identifier   = "tf-redshift-cluster"
  database_name        = "mydb"
  master_username      = "foo"
  master_password      = var.redshift_password
  node_type            = var.redshift_node_type
  cluster_type         = "single-node"
  publicly_accessible  = false
}

This disables public access. It does not by itself change subnets or create private connectivity for clients.

References