AWS RDS resource inventory

Associate databases with their services and owners.

Description

An RDS inventory documents the purpose and operational ownership of database assets. The presence of a resource is not itself a vulnerability.

Potential impact

Unlisted databases may be missed in backup, encryption, access-permission, and version-policy reviews.

Remediation

Record each database’s owner and service, then check backups, encryption, logging, access controls, and supported versions.

Examples

The examples add identification tags. The change-me password is illustrative and must not be used in a real environment. Access-policy and encryption configuration are unchanged, but check the effect of tag-based IAM policies.

Before

hcl
resource "aws_db_instance" "app" {
  allocated_storage = 20
  engine            = "mysql"
  instance_class    = "db.t3.micro"
  username          = "admin"
  password          = "change-me"
}

After

hcl
resource "aws_db_instance" "app" {
  allocated_storage = 20
  engine            = "mysql"
  instance_class    = "db.t3.micro"
  username          = "admin"
  password          = "change-me"

  tags = {
    Service     = "app-db"
    Environment = "production"
  }
}

References