For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/a7e-e88-302.md. A documentation index is available at /llms.txt.

Redshift clusters should not be publicly accessible

Description

Confirm Redshift clusters are not publicly available.

Rationale

Publicly available Redshift clusters have a public IP address, which gives any machine the opportunity to attempt to connect to your clusters. Malicious activity, such as SQL injections or distributed denial-of-service (DDoS) attacks, can occur if a connection is established.

Remediation

From the console

Follow the Managing clusters in a VPC docs to learn how to modify public accessibility for your clusters.