Description
An ElastiCache inventory documents the cache layer and how services use it. The presence of a cache resource alone does not establish a vulnerability.
Potential impact
An unlisted cache may be missed during network-access or engine-version reviews, or have unclear operational ownership.
Remediation
Record the service and owning team, then review authentication, encryption, security groups, and recovery options for the selected engine.
Examples
The examples add tags to a Memcached cluster. Tags do not enable access restrictions or data-protection features.
Before
hcl
resource "aws_elasticache_cluster" "cache" {
cluster_id = "app-cache"
engine = "memcached"
node_type = "cache.t3.small"
num_cache_nodes = 2
}
After
hcl
resource "aws_elasticache_cluster" "cache" {
cluster_id = "app-cache"
engine = "memcached"
node_type = "cache.t3.small"
num_cache_nodes = 2
tags = {
Service = "app"
Environment = "production"
}
}