If Internet access is disabled for all the endpoints of the PolarDB cluster, the evaluation result is Compliant.

Scenarios

Internet access to PolarDB clusters reduces network security. We recommend that you enable only virtual private cloud (VPC) access.

Risk level

Default risk level: high.

When you apply this rule, you can change the risk level based on your business requirements.

Compliance evaluation logic

  • If Internet access is disabled for all the endpoints of the PolarDB cluster, the evaluation result is Compliant.
  • If Internet access is enabled for any endpoint of the PolarDB cluster, the evaluation result is Incompliant. For more information about how to remediate an incompliant configuration, see the "Incompliance remediation" section of this topic.

Rule details

ParameterDescription
Rule namepolardb-cluster-address-no-public
Rule identifierpolardb-cluster-address-no-public
TagPolarDB
Automatic remediationNot supported
Trigger typePeriodic execution
Evaluation frequencyInterval of 24 hours
Supported resource typePolarDB cluster
Input parameterNone

Incompliance remediation

Disable Internet access for all endpoints of the PolarDB cluster. For more information, see Cluster endpoints and primary endpoints.