IaC Bazaar
AWSLive-tested

Redshift Cluster (encrypted, private)

A production-ready single-node Redshift cluster with encryption always on, never publicly accessible, a parameter group enforcing require_ssl, and a generated admin password stored in Secrets Manager.

terraformAWS#aws
aws-redshiftterraform v1.7

Verification

Live-tested

Really deployed, verified, idempotent and destroyed in a cloud sandbox.

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested — applied, verified, destroyed

Last verified 2026-06-30 · how we verify

Documentation

aws-redshift — Amazon Redshift Cluster

A production-ready Amazon Redshift cluster, single-node by default, with secure defaults baked in. Encryption is always on, the cluster is never publicly accessible, a dedicated parameter group enforces require_ssl, and the cluster gets a locked-down security group (no inbound rules unless you list allowed_cidrs). By default the admin password is generated and stored in Secrets Manager — it is never written to Terraform state.

Self-contained for quick trials: leave subnet_ids empty and the module discovers the subnets of the account's default VPC and derives the matching VPC for the security group.

Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.

What it provisions

  • aws_redshift_cluster — the cluster (encrypted, not publicly accessible).
  • aws_redshift_subnet_group — where the cluster's ENIs live.
  • aws_redshift_parameter_group — dedicated group with require_ssl = true.
  • aws_security_group + standalone ingress/egress rules — client access on the cluster port from allowed_cidrs (none by default); all egress for COPY/UNLOAD and enhanced VPC routing.

Requirements

  • Terraform or OpenTofu >= 1.6
  • hashicorp/aws >= 6.0, < 7.0

Verification

Static-validated (fmt, validate, tflint). Live apply/destroy testing pending cloud sandbox availability — see catalog status.

License

Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference unlock after purchase

The complete copy-paste usage, the full input/output reference, and operational notes ship with your licence — shown here and bundled in the download.

  • Usage
  • Inputs
  • Outputs
  • Security notes
  • Notes