IAM database authentication is not enabled for an RDS instance

Use IAM token authentication on supported RDS instances to reduce reliance on long-lived application passwords.

Description

IAM database authentication lets clients connect to supported RDS databases with an IAM token instead of a fixed password. Standard database authentication remains available when this feature is disabled, so disabling it does not mean the database has no authentication or is publicly accessible.

If you intend to manage connection permissions through IAM, enable the feature on a supported engine and version and configure clients to use it.

Potential impact

  • Distributing long-lived passwords across applications can increase the risk of disclosure and missed rotations.
  • Without IAM connection controls, database accounts and credentials may require separate management.

Remediation

  • Check engine, version, Region and client support, then set iam_database_authentication_enabled = true.
  • Configure database users for IAM authentication and the required rds-db:connect permissions, and use authentication tokens over TLS connections.
  • Check each account's existing authentication method and connection impact, and reduce unnecessary password use. This setting alone does not create database users or invalidate existing passwords.

Examples

These excerpts compare authentication settings for the same MySQL instance. Check support for the version and instance class, and configure networking, database users and IAM permissions separately. Supply db_password securely and restrict access to the Terraform state containing it.

Before

hcl
resource "aws_db_instance" "example" {
  allocated_storage                    = 20
  storage_type                         = "gp2"
  engine                               = "mysql"
  engine_version                       = "8.0"
  instance_class                       = "db.t2.micro"
  db_name                              = "mydb"
  username                             = "foo"
  password                             = var.db_password
  iam_database_authentication_enabled  = false
}

IAM token authentication is disabled. This does not mean database password authentication is absent.

After

hcl
resource "aws_db_instance" "example" {
  allocated_storage                    = 20
  storage_type                         = "gp2"
  engine                               = "mysql"
  engine_version                       = "8.0"
  instance_class                       = "db.t2.micro"
  db_name                              = "mydb"
  username                             = "foo"
  password                             = var.db_password
  iam_database_authentication_enabled  = true
}

This enables IAM authentication. Connections still require database users, IAM policies and clients configured to use tokens.

References