Database cluster IAM authentication is not enabled

Configure IAM authentication on supported database clusters to reduce shared long-term passwords.

Description

IAM database authentication lets applications connect to supported RDS or Aurora clusters with authentication tokens instead of long-term passwords. Sharing passwords across services without this option can make rotation and access management harder. Enabling IAM authentication does not automatically enable MFA or database audit logs.

Potential impact

A leaked shared or long-lived password can allow data access within the database user’s privileges.

Remediation

Confirm support for the cluster engine and version, then set EnableIAMDatabaseAuthentication: true. Configure database users for IAM authentication, the required rds-db:connect permissions and TLS, and test token-based application connections. Minimize database privileges and retire unnecessary password use.

Examples

These Aurora PostgreSQL cluster excerpts use inputs for a supported DBEngineVersion and its compatible DBClusterParameterGroupName. User and password inputs, networking and other definitions are omitted.

Before

yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
  sample:
    Type: "AWS::RDS::DBCluster"
    Properties:
      MasterUsername: !Ref DBUsername
      MasterUserPassword: !Ref DBPassword
      StorageEncrypted: true
      DBClusterIdentifier: aurora-postgresql-cluster
      Engine: aurora-postgresql
      EngineVersion: !Ref DBEngineVersion
      DBClusterParameterGroupName: !Ref DBClusterParameterGroupName
      EnableCloudwatchLogsExports:
        - postgresql
      EnableIAMDatabaseAuthentication: false

IAM authentication is disabled on the cluster. Credentials for other authentication methods still need to be managed.

After

yaml
AWSTemplateFormatVersion: "2010-09-09"
Resources:
  sample:
    Type: "AWS::RDS::DBCluster"
    Properties:
      MasterUsername: !Ref DBUsername
      MasterUserPassword: !Ref DBPassword
      StorageEncrypted: true
      DBClusterIdentifier: aurora-postgresql-cluster
      Engine: aurora-postgresql
      EngineVersion: !Ref DBEngineVersion
      DBClusterParameterGroupName: !Ref DBClusterParameterGroupName
      EnableCloudwatchLogsExports:
        - postgresql
      EnableIAMDatabaseAuthentication: true

IAM authentication becomes available on the cluster. This setting alone does not convert every existing account or application to that authentication method.

References