AWS Identity and Access Management (IAM) grants users access control across all Amazon Web Services. IAM supports granular permissions, giving you the ability to grant different permissions to different users. For more information on IAM and it's use cases, please refer to the IAM documentation.
Warning
To preserve compatibility with customers using the community driver, IAM Authentication requires the AWS Java SDK RDS v2.x to be included separately in the classpath. The AWS Java SDK RDS is a runtime dependency and must be resolved.
Since AWS Java SDK RDS v2.x size is around 5.4Mb (22Mb including all RDS SDK dependencies), some users may experience difficulties using the plugin due to limited available disk size. In such case, AWS Java SDK RDS v2.x required dependency may be replaced with just two required dependencies which have a smaller footprint (around 300Kb in total):
software.amazon.awssdk:http-client-spi
software.amazon.awssdk:auth
It's recommended to use AWS Java SDK RDS v2.x when it's possible.
To enable the IAM Authentication Connection Plugin, add the plugin code iam
to the wrapperPlugins
value, or to the current driver profile.
This plugin requires valid AWS credentials. See more details at AWS Credentials Configuration
The AWS JDBC Driver supports Amazon AWS Identity and Access Management (IAM) authentication. When using AWS IAM database authentication, the host URL must be a valid Amazon endpoint, and not a custom domain or an IP address.
ie. db-identifier.cluster-XYZ.us-east-2.rds.amazonaws.com
IAM database authentication use is limited to certain database engines. For more information on limitations and recommendations, please review the IAM documentation.
- Enable AWS IAM database authentication on an existing database or create a new database with AWS IAM database authentication on the AWS RDS Console:
- If needed, review the documentation about creating a new database.
- If needed, review the documentation about modifying an existing database.
- Set up an AWS IAM policy for AWS IAM database authentication.
- Create a database account using AWS IAM database authentication. This will be the user specified in the connection string or connection properties.
- Connect to your database of choice using primary logins.
- For a MySQL database, use the following command to create a new user:
CREATE USER example_user_name IDENTIFIED WITH AWSAuthenticationPlugin AS 'RDS';
- For a PostgreSQL database, use the following command to create a new user:
CREATE USER db_userx; GRANT rds_iam TO db_userx;
- For a MySQL database, use the following command to create a new user:
- Connect to your database of choice using primary logins.
- Add the plugin code
iam
to thewrapperPlugins
parameter value.
Parameter | Value | Required | Description | Example Value |
---|---|---|---|---|
iamDefaultPort |
String | No | This property will override the default port that is used to generate the IAM token. The default port is determined based on the underlying driver protocol. For now, there is support for jdbc:postgresql: and jdbc:mysql: . Target drivers with different protocols will require users to provide a default port. |
1234 |
iamHost |
String | No | This property will override the default hostname that is used to generate the IAM token. The default hostname is derived from the connection string. This parameter is required when users are connecting with custom endpoints. | database.cluster-hash.us-east-1.rds.amazonaws.com |
iamRegion |
String | No | This property will override the default region that is used to generate the IAM token. The default region is parsed from the connection string. | us-east-2 |
iamExpiration |
Integer | No | This property determines how long an IAM token is kept in the driver cache before a new one is generated. The default expiration time is set to be 14 minutes and 30 seconds. Note that IAM database authentication tokens have a lifetime of 15 minutes. | 600 |
AwsIamAuthenticationPostgresqlExample.java
AwsIamAuthenticationMysqlExample.java
AwsIamAuthenticationMariadbExample.java