AWS Redshift Terraform module

Upstream version 7.1.1
7 controls from AWS Well-Architected Framework v10 requirements

Terraform Module Source

awswellarchitected.compliance.tf/terraform-aws-modules/redshift/aws

Behavioral Summary

This module modifies 4 variable defaults and makes 0 resource changes from the upstream module. All changes are driven by compliance controls and can be reviewed in detail below.

Your Code Impact

If you are migrating from the upstream module, the enforced default changes mean your existing configurations will automatically gain compliance controls. Variables you have explicitly set will continue to use your values. Review the diff below to understand exactly what changes.

Compared to terraform-aws-modules/redshift/aws@7.1.14 changes

Variables Changed

4
VariableUpstreamCTFReasonControl
allow_version_upgrade-trueThis control checks whether automatic major version upgrades are enabled for the AWS Redshift cluster.redshift_cluster_automatic_upgrade_major_versions_enabled
cloudwatch_log_group_retention_in_days0365Ensure a minimum duration of event log data is retained for your log groups to help with troubleshooting and forensics investigations.cloudwatch_log_group_retention_period_365
encrypted-trueTo protect data at rest, ensure that encryption is enabled for your AWS Redshift clusters. You must also ensure that required configurations are deployed on AWS Redshift clusters. The audit logging should be enabled to provide information about connections and user activities in the database.redshift_cluster_encryption_logging_enabled
publicly_accessible-falseManage access to resources in the AWS Cloud by ensuring that AWS Redshift clusters are not public.redshift_cluster_prohibit_public_access