Configuring AssumeRole Authentication for Amazon Redshift V2 Connector

Configuring AssumeRole Authentication for Amazon Redshift V2 Connector

AssumeRole with a new database user

AssumeRole with a new database user

To connect to the Amazon Redshift database using the EC2 role to assume a role, specify the user name in the Amazon Redshift connection properties and select the
Use EC2 Role to AssumeRole
checkbox.
To assume a role using the EC2 role, you must attach the following policies to the EC2 role in the AWS console:
  • AWS IAM EC2 policy that enables you to assume a role:
    EC2 policy to attach to EC2 instance
  • The trust relationship of the EC2 role to assume a role:
    Trust policy to EC2 role to assume a role
  • Trust relationship of the Redshift role to enable the EC2 role to assume a role:
    Trust relationship in Redshift role
  • You can attach the following policy in AWS to a Redshift role for a new database user:
    Permission policy for existing database user
The following image shows an example of the configured connection properties:
To assume a role using the existing database user

0 COMMENTS

We’d like to hear from you!