Redshift Cluster (encrypted, private)
A production-ready single-node Redshift cluster with encryption always on, never publicly accessible, a parameter group enforcing require_ssl, and a generated admin password stored in Secrets Manager.
Verification
Live-testedReally deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan test superseded by live test
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-06-30 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o aws-redshift-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/aws-redshift/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle aws-redshift-1.0.0.sigstore.json \
aws-redshift-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "51f01212a87836435c184c4e0618d0620271cc8fe53c0d5bcd0ad3dbed425f2e aws-redshift-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "redshift" {
source = "www.iac-bazaar.com/iac-bazaar/aws-redshift/aws"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/aws-redshift?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Terraform module 1.0.0, live-tested on IaC Bazaar: [Redshift Cluster (encrypted, private)](https://www.iac-bazaar.com/catalog/aws-redshift?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```hcl
module "redshift" {
source = "www.iac-bazaar.com/iac-bazaar/aws-redshift/aws"
version = "1.0.0"
}
```Preview:
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
aws-redshift — Amazon Redshift Cluster
A production-ready Amazon Redshift cluster, single-node by default, with
secure defaults baked in. Encryption is always on, the cluster is never
publicly accessible, a dedicated parameter group enforces require_ssl, and
the cluster gets a locked-down security group (no inbound rules unless you
list allowed_cidrs). By default the admin password is generated and stored in
Secrets Manager — it is never written to Terraform state.
Self-contained for quick trials: leave subnet_ids empty and the module
discovers the subnets of the account's default VPC and derives the matching
VPC for the security group.
Works with Terraform and OpenTofu (>= 1.6), AWS provider >= 6.0, < 7.0.
What it provisions
aws_redshift_cluster— the cluster (encrypted, not publicly accessible).aws_redshift_subnet_group— where the cluster's ENIs live.aws_redshift_parameter_group— dedicated group withrequire_ssl = true.aws_redshift_logging(optional) — audit logs to CloudWatch Logs or S3 whenloggingis set (the provider-v6 replacement for the removed inlineloggingblock).aws_security_group+ standalone ingress/egress rules — client access on the cluster port fromallowed_cidrs(none by default); all egress for COPY/UNLOAD and enhanced VPC routing.
Security notes
- Encryption is always on (
encrypted = true); supplykms_key_arnfor a customer-managed key, otherwise the AWS-managedaws/redshiftkey is used. - Never public —
publicly_accessibleis hard-wired tofalse. - TLS enforced — the dedicated parameter group sets
require_ssl = true. - No open ingress — the security group has no inbound rule unless you list
allowed_cidrs; there is no0.0.0.0/0default. - Password stays out of state — leave
master_passwordnull to use a Secrets-Manager-managed credential.
Requirements
- Terraform or OpenTofu
>= 1.6 hashicorp/aws>= 6.0, < 7.0
License
Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- Inputs
- Outputs
- Notes
Related modules
aws-keyspaces
point_in_time_recovery defaults to DISABLED and Keyspaces has no snapshots or automated backups, so off means a dropped table is simply gone. PITR on, a customer-managed key, and the two one-way doors - client-side timestamps and TTL - named rather than set quietly.
aws-database-proxy
Amazon RDS Proxy in front of an RDS instance or Aurora cluster: TLS required, clients authenticate with IAM tokens while the proxy reads the password from Secrets Manager, through a role limited to those secrets. Debug logging writes SQL statement text to the logs, so it is off unless that is accepted. End-to-end IAM removes the stored password entirely.
aws-dax-cache
DynamoDB Accelerator with TLS and encryption at rest. DAX leaves both off by default, and neither can be turned on for an existing cluster, so a fix means a new cluster. This module also creates its own security group (DAX otherwise uses the VPC default), a service role limited to the named tables and their indexes, and states that writes bypassing DAX leave stale reads until the TTL.
aws-neptune
Neptune has no user, no password and no GRANT. Authorization is IAM and it defaults to OFF, so anything that can reach port 8182 can read every edge and drop the lot. IAM auth on, storage encrypted, and the audit log driven from one variable because its two halves live in different resources and either alone logs nothing.
aws-dms
ssl_mode defaults to none in AWS, so a task reads your entire production database and writes it elsewhere unencrypted. This defaults to require, refuses none unless stated, and pushes the credential into Secrets Manager rather than state.
aws-quicksight
A QuickSight subscription on Enterprise edition through IAM Identity Center, with admin, author and reader groups, termination protection on because unsubscribing deletes every dashboard, and a VPC connection with its own role so a private database stays private. The authentication method is permanent; Standard edition and QuickSight-managed users are accepted by name.