Check provider logo

DMS replication instance has auto minor version upgrade enabled

dms_instance_minor_version_upgrade_enabled

Severitymedium
Servicedms
by Prowler

AWS DMS replication instances are evaluated for the auto_minor_version_upgrade setting to confirm automatic minor engine updates are enabled during the maintenance window.

Risk

Without automatic minor upgrades, DMS engines can miss security patches and fixes, enabling exploitation of known flaws and instability.

  • Confidentiality: exposure via unpatched components
  • Integrity: replication errors or data drift
  • Availability: outages during migration or CDC
Run this check with Prowler CLI

prowler aws --checks dms_instance_minor_version_upgrade_enabled

Recommendation

Enable auto_minor_version_upgrade on all replication instances to maintain continuous patching.

  • Set a maintenance window and validate in non-prod
  • Monitor release notes and health metrics
  • Enforce least privilege for change control
  • Keep backups for rollback

Remediation

CLI

aws dms modify-replication-instance --region <REGION> --replication-instance-arn arn:aws:dms:<REGION>:<ACCOUNT_ID>:rep:<REPLICATION_ID> --auto-minor-version-upgrade --apply-immediately

Native IaC
Terraform
Other
  1. Open the AWS Console and go to Database Migration Service (DMS)
  2. Click Replication instances and select your instance
  3. Choose Actions > Modify
  4. Check Auto minor version upgrade
  5. Select Apply immediately
  6. Click Modify to save

Source Code

Resource Type

AwsDmsReplicationInstance

References