Description
IAM database authentication lets applications connect to supported RDS or Aurora clusters with authentication tokens instead of long-term passwords. Sharing passwords across services without this option can make rotation and access management harder. Enabling IAM authentication does not automatically enable MFA or database audit logs.
Potential impact
A leaked shared or long-lived password can allow data access within the database user’s privileges.
Remediation
Confirm support for the cluster engine and version, then set EnableIAMDatabaseAuthentication: true. Configure database users for IAM authentication, the required rds-db:connect permissions and TLS, and test token-based application connections. Minimize database privileges and retire unnecessary password use.
Examples
These Aurora PostgreSQL cluster excerpts use inputs for a supported DBEngineVersion and its compatible DBClusterParameterGroupName. User and password inputs, networking and other definitions are omitted.
Before
AWSTemplateFormatVersion: "2010-09-09"
Resources:
sample:
Type: "AWS::RDS::DBCluster"
Properties:
MasterUsername: !Ref DBUsername
MasterUserPassword: !Ref DBPassword
StorageEncrypted: true
DBClusterIdentifier: aurora-postgresql-cluster
Engine: aurora-postgresql
EngineVersion: !Ref DBEngineVersion
DBClusterParameterGroupName: !Ref DBClusterParameterGroupName
EnableCloudwatchLogsExports:
- postgresql
EnableIAMDatabaseAuthentication: false
IAM authentication is disabled on the cluster. Credentials for other authentication methods still need to be managed.
After
AWSTemplateFormatVersion: "2010-09-09"
Resources:
sample:
Type: "AWS::RDS::DBCluster"
Properties:
MasterUsername: !Ref DBUsername
MasterUserPassword: !Ref DBPassword
StorageEncrypted: true
DBClusterIdentifier: aurora-postgresql-cluster
Engine: aurora-postgresql
EngineVersion: !Ref DBEngineVersion
DBClusterParameterGroupName: !Ref DBClusterParameterGroupName
EnableCloudwatchLogsExports:
- postgresql
EnableIAMDatabaseAuthentication: true
IAM authentication becomes available on the cluster. This setting alone does not convert every existing account or application to that authentication method.