publicly Accessible
Specifies whether the DB shard group is publicly accessible. When the DB shard group is publicly accessible, its Domain Name System (DNS) endpoint resolves to the private IP address from within the DB shard group's virtual private cloud (VPC). It resolves to the public IP address from outside of the DB shard group's VPC. Access to the DB shard group is ultimately controlled by the security group it uses. That public access is not permitted if the security group assigned to the DB shard group doesn't permit it. When the DB shard group isn't publicly accessible, it is an internal DB shard group with a DNS name that resolves to a private IP address. Default: The default behavior varies depending on whether `DBSubnetGroupName`
is specified. If `DBSubnetGroupName`
isn't specified, and `PubliclyAccessible`
isn't specified, the following applies:
If the default VPC in the target Region doesn’t have an internet gateway attached to it, the DB shard group is private.
If the default VPC in the target Region has an internet gateway attached to it, the DB shard group is public. If
`DBSubnetGroupName`
is specified, and`PubliclyAccessible`
isn't specified, the following applies:If the subnets are part of a VPC that doesn’t have an internet gateway attached to it, the DB shard group is private.
If the subnets are part of a VPC that has an internet gateway attached to it, the DB shard group is public.