Review IAM database authentication for RDS

Reduce reliance on long-lived passwords with IAM authentication where RDS supports it.

Description

RDS IAM database authentication uses short-lived authentication tokens in supported MariaDB, MySQL, and PostgreSQL environments. Without it, separate database credentials may need storage and rotation.

Potential impact

Leaked long-lived passwords can be abused until replaced, while credentials distributed across applications increase management effort.

Remediation

Check engine, version, instance-type, and application support before enabling enable_iam_database_authentication. Configure database users, IAM permissions, and TLS connections as well; the instance setting alone does not migrate existing logins.

Examples

The examples compare only the instance’s IAM authentication setting. Supply a supported instance class and configure users and applications separately.

Before

yaml
- name: RDS 인스턴스 생성
  amazon.aws.rds_instance:
    engine: mariadb
    id: test-db
    state: present
    db_instance_class: "{{ db_instance_class }}"
    username: "{{ username }}"
    password: "{{ password }}"
    allocated_storage: "{{ allocated_storage }}"
    enable_iam_database_authentication: false

After

yaml
- name: RDS 인스턴스 생성
  amazon.aws.rds_instance:
    engine: mariadb
    id: test-db
    state: present
    db_instance_class: "{{ db_instance_class }}"
    username: "{{ username }}"
    password: "{{ password }}"
    allocated_storage: "{{ allocated_storage }}"
    enable_iam_database_authentication: true

References