Checks if Amazon ElastiCache replication groups have RBAC authentication enabled. The rule is NON_COMPLIANT if the Redis version is 6 or above and ‘UserGroupIds’ is missing, empty, or does not match an entry provided by the 'allowedUserGroupIDs' parameter.

This config rule supports the following parameters:

  • allowedUserGroupIDs
    • Required: No
    • Type: CSV
    • Description:A comma-separated list of User Group IDs that are approved for ElastiCache replication group access.

ConfigRule
AWS::Config::ConfigRule


Source *
CustomPolicyDetails
SourceDetails

CloudFormation Template

Share Template