Description
Clusters that support IAM database authentication allow connections with IAM tokens instead of fixed passwords. This can reduce password storage in applications and centralize connection permissions in IAM policies.
Disabling IAM authentication does not by itself leave a database open without authentication. Standard database authentication is available, and adopting IAM authentication depends on supported engines, versions and operational requirements.
Potential impact
- Long-lived passwords retained by multiple applications can increase the risk of disclosure and missed rotations.
- Environments that require IAM connection controls may otherwise need to manage accounts and credentials separately.
Remediation
- Check engine, version, Region and instance-class support, then set
iam_database_authentication_enabled = true. - Configure IAM database users, the required
rds-db:connectpermissions and TLS token connections. Limit each user's data operations separately. - Verify application connections before retiring existing authentication methods. Depending on the engine, a user configured for IAM authentication cannot use password login, so assess each account's impact first.
Examples
These excerpts compare authentication for the same Aurora MySQL cluster. Check that the example version and Availability Zones suit your environment, and configure DB instances, networking and user permissions separately. Supply db_password securely and protect its value in Terraform state.
Before
resource "aws_rds_cluster" "example" {
cluster_identifier = "example-cluster"
engine = "aurora-mysql"
engine_version = "8.0.mysql_aurora.3.05.2"
master_username = "username"
master_password = var.db_password
iam_database_authentication_enabled = false
availability_zones = ["us-east-1a", "us-east-1b", "us-east-1c"]
skip_final_snapshot = true
}
IAM database authentication is disabled for the cluster. Separate database authentication and password management are required.
After
resource "aws_rds_cluster" "example" {
cluster_identifier = "example-cluster"
engine = "aurora-mysql"
engine_version = "8.0.mysql_aurora.3.05.2"
master_username = "username"
master_password = var.db_password
iam_database_authentication_enabled = true
availability_zones = ["us-east-1a", "us-east-1b", "us-east-1c"]
skip_final_snapshot = true
}
Enabling IAM authentication does not automatically migrate database users or clients. Apply the necessary permissions and connection settings as well.