Hi, I'm Ask INFA!
What would you like to know?
ASK INFAPreview
Please to access Ask INFA.

Configuring AssumeRole Authentication for Amazon Redshift V2 Connector

Configuring AssumeRole Authentication for Amazon Redshift V2 Connector

AssumeRole with a new database user

AssumeRole with a new database user

To connect to the Amazon Redshift database using the EC2 role to assume a role, specify the user name in the Amazon Redshift connection properties and select the
Use EC2 Role to AssumeRole
checkbox.
To assume a role using the EC2 role, you must attach the following policies to the EC2 role in the AWS console:
  • AWS IAM EC2 policy that enables you to assume a role:
    EC2 policy to attach to EC2 instance
  • The trust relationship of the EC2 role to assume a role:
    Trust policy to EC2 role to assume a role
  • Trust relationship of the Redshift role to enable the EC2 role to assume a role:
    Trust relationship in Redshift role
  • You can attach the following policy in AWS to a Redshift role for a new database user:
    Permission policy for existing database user
The following image shows an example of the configured connection properties:
To assume a role using the existing database user

0 COMMENTS

We’d like to hear from you!