Description
RDS IAM database authentication uses short-lived authentication tokens in supported MariaDB, MySQL, and PostgreSQL environments. Without it, separate database credentials may need storage and rotation.
Potential impact
Leaked long-lived passwords can be abused until replaced, while credentials distributed across applications increase management effort.
Remediation
Check engine, version, instance-type, and application support before enabling enable_iam_database_authentication. Configure database users, IAM permissions, and TLS connections as well; the instance setting alone does not migrate existing logins.
Examples
The examples compare only the instance’s IAM authentication setting. Supply a supported instance class and configure users and applications separately.
Before
- name: RDS 인스턴스 생성
amazon.aws.rds_instance:
engine: mariadb
id: test-db
state: present
db_instance_class: "{{ db_instance_class }}"
username: "{{ username }}"
password: "{{ password }}"
allocated_storage: "{{ allocated_storage }}"
enable_iam_database_authentication: false
After
- name: RDS 인스턴스 생성
amazon.aws.rds_instance:
engine: mariadb
id: test-db
state: present
db_instance_class: "{{ db_instance_class }}"
username: "{{ username }}"
password: "{{ password }}"
allocated_storage: "{{ allocated_storage }}"
enable_iam_database_authentication: true