IAM database authentication is not enabled for an RDS cluster

Manage connection permissions with IAM token authentication on supported database clusters.

Description

Clusters that support IAM database authentication allow connections with IAM tokens instead of fixed passwords. This can reduce password storage in applications and centralize connection permissions in IAM policies.

Disabling IAM authentication does not by itself leave a database open without authentication. Standard database authentication is available, and adopting IAM authentication depends on supported engines, versions and operational requirements.

Potential impact

  • Long-lived passwords retained by multiple applications can increase the risk of disclosure and missed rotations.
  • Environments that require IAM connection controls may otherwise need to manage accounts and credentials separately.

Remediation

  • Check engine, version, Region and instance-class support, then set iam_database_authentication_enabled = true.
  • Configure IAM database users, the required rds-db:connect permissions and TLS token connections. Limit each user's data operations separately.
  • Verify application connections before retiring existing authentication methods. Depending on the engine, a user configured for IAM authentication cannot use password login, so assess each account's impact first.

Examples

These excerpts compare authentication for the same Aurora MySQL cluster. Check that the example version and Availability Zones suit your environment, and configure DB instances, networking and user permissions separately. Supply db_password securely and protect its value in Terraform state.

Before

hcl
resource "aws_rds_cluster" "example" {
  cluster_identifier = "example-cluster"

  engine         = "aurora-mysql"
  engine_version = "8.0.mysql_aurora.3.05.2"

  master_username = "username"
  master_password = var.db_password

  iam_database_authentication_enabled = false

  availability_zones = ["us-east-1a", "us-east-1b", "us-east-1c"]

  skip_final_snapshot = true
}

IAM database authentication is disabled for the cluster. Separate database authentication and password management are required.

After

hcl
resource "aws_rds_cluster" "example" {
  cluster_identifier = "example-cluster"

  engine         = "aurora-mysql"
  engine_version = "8.0.mysql_aurora.3.05.2"

  master_username = "username"
  master_password = var.db_password

  iam_database_authentication_enabled = true

  availability_zones = ["us-east-1a", "us-east-1b", "us-east-1c"]

  skip_final_snapshot = true
}

Enabling IAM authentication does not automatically migrate database users or clients. Apply the necessary permissions and connection settings as well.

References