是否有可能在使用AWS CDK创建的Aurora数据库上“要求SSL”?我们已经启用了加密,但这只是“处于静止状态”,我们还需要加密“正在传输”,并被安全监视器标记,因为数据库不“需要SSL”。
下面是我们用来设置数据库的代码:
const cluster = new rds.DatabaseCluster(scope, 'TheDB', {
defaultDatabaseName: dbName,
engine: rds.DatabaseClusterEngine.auroraPostgres({ version: rds.AuroraPostgresEngineVersion.VER_13_7 }),
credentials: {
username: dbUser,
password: pgPasswordSecret.secretValue,
},
instanceProps: {
securityGroups: [securityGroup],
instanceType: primaryPostgresInstanceType(),
vpcSubnets: {
subnetType: ec2.SubnetType.PRIVATE_WITH_NAT,
},
vpc,
},
storageEncrypted: true,
backup: {
retention: Duration.days(15),
},})
发布于 2022-08-16 17:41:54
解决方案(来自https://gitter.im/awslabs/aws-cdk?at=5e2ab552f196225bd64b7581)是在创建数据库集群时传递一个parameterGroup,将rds.force_ssl设置为'1'
const postgresVersion = rds.AuroraPostgresEngineVersion.VER_13_7
const parameterGroup = new rds.ParameterGroup(scope, 'ClusterParameterGroup', {
engine: rds.DatabaseClusterEngine.auroraPostgres({ version: postgresVersion}),
parameters: {
'rds.force_ssl': '1',
},
})
const cluster = new rds.DatabaseCluster(scope, 'TheDB', {
...
parameterGroup,
...
})https://stackoverflow.com/questions/73366671
复制相似问题