aws-rds: CloudFormation Validate W9008 false positive on Aurora cluster instances
Describe the bug
The built-in CloudFormation Validate rule W9008 ("RDS instance should have StorageEncrypted set to true") is raised against the instance resources of an Aurora rds.DatabaseCluster even when the cluster sets storage_encrypted=True.
For Aurora, storage encryption is a cluster-level property. Per the CloudFormation documentation for AWS::RDS::DBInstance.StorageEncrypted, encryption for Aurora DB instances is managed by the DB cluster, so cluster member instances are expected not to carry StorageEncrypted. The rule flags them regardless, which makes every encrypted Aurora cluster synth with a warning, and fails synthesis for apps that run cdk synth --strict.
Regression Issue
- Select this option if this issue appears to be a regression.
Worked before the CloudFormation Validate default rules were introduced (2.262.0); pipelines running cdk synth --strict against unpinned aws-cdk-lib started failing with no code change.
Last Known Working CDK Library Version
2.261.x
Expected Behavior
No W9008 finding for instances that belong to an Aurora DatabaseCluster with storage_encrypted=True (or to any Aurora cluster, since the property is not applicable at instance level).
Current Behavior
WARNING RDS instance should have StorageEncrypted set to true (CloudFormation Validate)
MyStack/AuroraCluster/writer/Resource (AuroraClusterwriter...) aws-cdk-lib.aws_rds.CfnDBInstance
Suggested fix: Set StorageEncrypted to true
Acknowledge with 'CloudFormation-Validate::W9008'
Synthesis finished with warnings (--strict mode)cdk synth --strict exits 1.
Reproduction Steps
from aws_cdk import App, Stack, aws_ec2 as ec2, aws_rds as rds
app = App()
stack = Stack(app, "MyStack")
vpc = ec2.Vpc(stack, "Vpc")
rds.DatabaseCluster(
stack,
"AuroraCluster",
engine=rds.DatabaseClusterEngine.aurora_postgres(
version=rds.AuroraPostgresEngineVersion.VER_16_4
),
vpc=vpc,
serverless_v2_min_capacity=0.5,
serverless_v2_max_capacity=2.0,
writer=rds.ClusterInstance.serverless_v2("writer"),
storage_encrypted=True,
)
app.synth()Run cdk synth --strict.
Possible Solution
Skip the W9008 check for AWS::RDS::DBInstance resources that reference a DBClusterIdentifier, or evaluate the rule against the owning AWS::RDS::DBCluster's StorageEncrypted instead.
Additional Information/Context
Workaround that unblocks --strict pipelines, scoped to the cluster:
from aws_cdk import Acknowledgment, Validations
Validations.of(cluster).acknowledge(
Acknowledgment(
id="CloudFormation-Validate::W9008",
reason="Aurora encryption is configured at cluster level (storage_encrypted=True).",
)
)CDK CLI Version
2.1132.1 (build 237e1b2)
Framework Version
aws-cdk-lib 2.262.0
Node.js Version
24.18.0
OS
macOS 15 (also reproduced on Linux CI runners)
Language
Python
Language Version
3.12
Source: aws/aws-cdk