AWS neptune: Note: deletion protection does not block read-replica scale-in
Summary
Adds a note clarifying that read-replica auto-scaling removes readers via the Neptune API, so cluster deletion protection does not prevent scale-in; min-capacity controls the minimum readers.
Security assessment
Clarifies the scope/limitations of deletion protection (a data-protection control) relative to auto-scaling, helping users avoid a false sense of protection against replica removal. Documentation of a security-relevant control's boundaries, not a fix for a specific vulnerability.
Evidence
+Read-replica auto-scaling removes readers through the Neptune API, so cluster deletion protection does not prevent a scale-in activity from removing a read replica. Deletion protection blocks deletion of the DB cluster itself, not the removal of individual read replicas. The `min-capacity` of your scaling policy determines the minimum number of readers that auto-scaling maintains. For more information about deletion protection, see [How deletion protection affects DB instance deletion](./manage-console-instances-delete.html#manage-console-instances-deletion-protection).
Diff
diff --git a/neptune/latest/userguide/manage-console-autoscaling.md b/neptune/latest/userguide/manage-console-autoscaling.md index 5fd54227e..81f4d481b 100644 --- a//neptune/latest/userguide/manage-console-autoscaling.md +++ b//neptune/latest/userguide/manage-console-autoscaling.md @@ -44,0 +45,4 @@ Neptune auto-scaling only removes replicas that it created. It does not remove p +###### Note + +Read-replica auto-scaling removes readers through the Neptune API, so cluster deletion protection does not prevent a scale-in activity from removing a read replica. Deletion protection blocks deletion of the DB cluster itself, not the removal of individual read replicas. The `min-capacity` of your scaling policy determines the minimum number of readers that auto-scaling maintains. For more information about deletion protection, see [How deletion protection affects DB instance deletion](./manage-console-instances-delete.html#manage-console-instances-deletion-protection). +