Description
An RDS inventory documents the purpose and operational ownership of database assets. The presence of a resource is not itself a vulnerability.
Potential impact
Unlisted databases may be missed in backup, encryption, access-permission, and version-policy reviews.
Remediation
Record each database’s owner and service, then check backups, encryption, logging, access controls, and supported versions.
Examples
The examples add identification tags. The change-me password is illustrative and must not be used in a real environment. Access-policy and encryption configuration are unchanged, but check the effect of tag-based IAM policies.
Before
hcl
resource "aws_db_instance" "app" {
allocated_storage = 20
engine = "mysql"
instance_class = "db.t3.micro"
username = "admin"
password = "change-me"
}
After
hcl
resource "aws_db_instance" "app" {
allocated_storage = 20
engine = "mysql"
instance_class = "db.t3.micro"
username = "admin"
password = "change-me"
tags = {
Service = "app-db"
Environment = "production"
}
}