Review Redshift default ports and access controls

Limit Redshift connections independently of the chosen port number.

Description

The default Amazon Redshift cluster port is 5439. A well-known number can help identify a service, but it does not itself provide public access or bypass authentication. A different port still requires security-group controls and database authentication.

Potential impact

  • Broad network permissions can admit unwanted connections and authentication attacks.
  • Relying on a port change can leave actual access-control gaps unaddressed.

Remediation

Review public accessibility, routing, and security groups to allow only required clients, and retain authentication and encryption. If choosing another port, check support for the node type and update application connection settings and network rules.

Examples

These excerpts compare port settings for a single-node DC2 cluster. The password is illustrative and must be managed separately in deployment; networking is also omitted.

Before

hcl
resource "aws_redshift_cluster" "example" {
  cluster_identifier  = "tf-redshift-cluster"
  database_name       = "mydb"
  master_username     = "foo"
  master_password     = "Mustbe8characters"
  node_type           = "dc2.large"
  cluster_type        = "single-node"
  publicly_accessible = false
}

After

hcl
resource "aws_redshift_cluster" "example" {
  cluster_identifier  = "tf-redshift-cluster"
  database_name       = "mydb"
  master_username     = "foo"
  master_password     = "Mustbe8characters"
  node_type           = "dc2.large"
  cluster_type        = "single-node"
  publicly_accessible = false
  port                = 1150
}

The first uses the default 5439; the second specifies 1150. Both disable public accessibility, but verify the VPC paths and security groups to establish which connections are actually allowed.

References