Other Articles

RDS DB Instance – Enable Auto Minor Version Upgrade

This check ensures that automatic minor version upgrades are enabled for Amazon RDS database instances. Enabling this setting helps keep databases up to date with security patches and minor feature improvements with minimal operational effort.

Check Details

  • Resource: RDS DB Instance
  • Check: Enable auto minor version upgrade
  • Risk: Missing important security patches and minor database fixes

Remediation via AWS Console

  1. Log in to the AWS Management Console and navigate to the Amazon RDS dashboard. Amazon RDS dashboard
  2. In the left navigation pane, click Databases.
  3. Select the RDS instance that you want to update.
  4. Click the Modify button at the top-right of the page. Modify RDS instance
  5. Scroll down to the Maintenance section and enable Auto minor version upgrade. Enable auto minor version upgrade
  6. Scroll to the bottom of the page, click Continue, then choose Modify DB instance.

Remediation via AWS CLI

  1. Log in to the AWS Management Console and click the CloudShell icon (>_) in the top-right corner. AWS CloudShell
  2. List all RDS instances in the selected AWS region:
    
    
    aws rds describe-db-instances \
     --region <region-name> \
     --query 'DBInstances[*].DBInstanceIdentifier'
    
    RDS output
  3. Enable automatic minor version upgrades for the selected database (apply immediately):
    
    
    aws rds modify-db-instance \
     --region <region-name> \
     --db-instance-identifier <db-instance-identifier> \
     --auto-minor-version-upgrade \
     --apply-immediately
    
  4. Verify that auto minor version upgrades are enabled:
    
    
    aws rds describe-db-instances \
     --region <region-name> \
     --db-instance-identifier <db-instance-identifier> \
     --query 'DBInstances[*].AutoMinorVersionUpgrade'
    

Confirm the output returns true, indicating that automatic minor version upgrades are enabled for the RDS instance.