Neptune cluster has IAM database authentication disabled

Apply IAM authentication and the required data permissions to Neptune requests.

Description

Enabling IAM database authentication for Neptune requires AWS Signature Version 4 (SigV4) signatures on requests and uses IAM policies to control data access. With this feature disabled, these IAM request authentication and permission checks do not apply.

Configure authentication alongside network restrictions so that network reachability alone does not permit data operations. Encryption at rest does not replace request authentication.

Potential impact

  • Clients that do not need data access may read or change data if they can connect to Neptune.
  • A compromised internal system may exploit a data access path that lacks IAM restrictions.

Remediation

  • Prepare SigV4 signing and the required data permissions for clients, then set iam_database_authentication_enabled = true.
  • Plan maintenance: changing the authentication setting restarts the engine and terminates existing connections.
  • Restrict security groups and connection paths to required clients, and verify that authorized requests succeed and unauthorized requests are rejected.

Examples

These excerpts compare authentication settings for the same cluster. DB instances, subnets, security groups and client settings require separate configuration.

Before

hcl
resource "aws_neptune_cluster" "neptune_cluster" {
  cluster_identifier                  = "neptune-cluster-demo"
  engine                              = "neptune"
  storage_encrypted                   = true
  iam_database_authentication_enabled = false
}

Encryption at rest is enabled, but IAM database authentication is disabled.

After

hcl
resource "aws_neptune_cluster" "neptune_cluster" {
  cluster_identifier                  = "neptune-cluster-demo"
  engine                              = "neptune"
  storage_encrypted                   = true
  iam_database_authentication_enabled = true
}

This enables IAM authentication. Client request signing and data permissions must be ready before the change is applied.

References