AWS redshift: Redshift Spectrum enhanced VPC routing endpoint requirements clarified
Summary
Rewrites two Spectrum considerations: with enhanced VPC routing turned on, queries against S3 data lake tables require VPC endpoints for Amazon S3 and AWS Glue, and notes Spectrum scans S3 data on an AWS-managed fleet outside the customer VPC; also updates the cross-reference link text.
Security assessment
Clarifies network-path security expectations: required S3/Glue VPC endpoints under enhanced VPC routing and the important caveat that data-scan traffic does not traverse the customer VPC even with EVR enabled, which affects assumptions about network isolation and egress controls; no specific vulnerability or CVE is referenced.
Evidence
+ * When enhanced VPC routing is turned on, Redshift Spectrum queries against data lake tables in Amazon S3 require VPC endpoints for Amazon S3 and AWS Glue so the cluster can reach your data and catalog. Note that Spectrum scans your Amazon S3 data on an AWS-managed fleet outside your VPC, so this data-scan traffic doesn't pass through your VPC even with enhanced VPC routing turned on. For configuration steps, see [Querying data lake tables with enhanced VPC routing](https://docs.aws.amazon.com/redshift/latest/mgmt/spectrum-enhanced-vpc.html) in the _Amazon Redshift Management Guide_.
Diff
diff --git a/redshift/latest/dg/c-spectrum-considerations.md b/redshift/latest/dg/c-spectrum-considerations.md index 7ce4d2696..5e6aefa85 100644 --- a//redshift/latest/dg/c-spectrum-considerations.md +++ b//redshift/latest/dg/c-spectrum-considerations.md @@ -17 +17 @@ Note the following considerations when you use Redshift Spectrum: - * Redshift Spectrum doesn't support enhanced VPC routing with RA3 and DC2 provisioned clusters. To access your Amazon S3 data, you might need to perform additional configuration steps. For more information, see [Redshift Spectrum and enhanced VPC routing](https://docs.aws.amazon.com/redshift/latest/mgmt/spectrum-enhanced-vpc.html) in the _Amazon Redshift Management Guide_. + * When enhanced VPC routing is turned on, Redshift Spectrum queries against data lake tables in Amazon S3 require VPC endpoints for Amazon S3 and AWS Glue so the cluster can reach your data and catalog. Note that Spectrum scans your Amazon S3 data on an AWS-managed fleet outside your VPC, so this data-scan traffic doesn't pass through your VPC even with enhanced VPC routing turned on. For configuration steps, see [Querying data lake tables with enhanced VPC routing](https://docs.aws.amazon.com/redshift/latest/mgmt/spectrum-enhanced-vpc.html) in the _Amazon Redshift Management Guide_. @@ -19 +19 @@ Note the following considerations when you use Redshift Spectrum: - * Redshift Spectrum supports Amazon S3 access point aliases. For more information, see [Using a bucket–style alias for your access point](https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-points-alias.html) in the _Amazon Simple Storage Service User Guide_. However, Redshift Spectrum doesn't support VPC with Amazon S3 access point aliases. For more information, see [Redshift Spectrum and enhanced VPC routing](https://docs.aws.amazon.com/redshift/latest/mgmt/spectrum-enhanced-vpc.html) in the _Amazon Redshift Management Guide_. + * Redshift Spectrum supports Amazon S3 access point aliases. For more information, see [Using a bucket–style alias for your access point](https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-points-alias.html) in the _Amazon Simple Storage Service User Guide_. However, Redshift Spectrum doesn't support VPC with Amazon S3 access point aliases. For more information, see [Querying data lake tables with enhanced VPC routing](https://docs.aws.amazon.com/redshift/latest/mgmt/spectrum-enhanced-vpc.html) in the _Amazon Redshift Management Guide_.