AWS Security ChangesHomeSearch

AWS AmazonRDS: Added reserved users rdsproxyadmin and rdsrepladmin in MariaDB 12.3

Service: AmazonRDS · 2026-08-12 · Documentation medium

File: AmazonRDS/latest/UserGuide/MariaDB.Concepts.UsersAndPrivileges.md · Type: authz

Summary

Documented protection against dropping/modifying critical system accounts (rdsproxyadmin and rdsrepladmin) in MariaDB 12.3+.

Security assessment

Prevents accidental or malicious removal of system accounts required for RDS Proxy and replication, reducing privilege escalation risks.

Evidence

Starting with RDS for MariaDB version 12.3, `rdsproxyadmin` is also a reserved user.

Diff

diff --git a/AmazonRDS/latest/UserGuide/MariaDB.Concepts.UsersAndPrivileges.md b/AmazonRDS/latest/UserGuide/MariaDB.Concepts.UsersAndPrivileges.md
index 24d2b2e62..302b42053 100644
--- a//AmazonRDS/latest/UserGuide/MariaDB.Concepts.UsersAndPrivileges.md
+++ b//AmazonRDS/latest/UserGuide/MariaDB.Concepts.UsersAndPrivileges.md
@@ -88,0 +89,17 @@ To provide management services for each DB instance, the `rdsadmin` user is crea
+Starting with RDS for MariaDB version 12.3, `rdsproxyadmin` is also a reserved user. Amazon RDS creates this user the first time you register a DB instance as a target for a proxy. Attempting to create, drop, rename, or modify the `rdsproxyadmin` account at any host results in an error similar to the following:
+    
+    
+    mysql> DROP USER 'rdsproxyadmin'@'%';
+    ERROR 1396 (HY000): Operation DROP USER failed for 'rdsproxyadmin'@'%'
+    
+    mysql> DROP USER 'rdsproxyadmin'@'host';
+    ERROR 1396 (HY000): Operation DROP USER failed for 'rdsproxyadmin'@'host'
+
+For more information about the RDS Proxy monitoring user, see [Amazon RDS Proxy](./rds-proxy.html).
+
+The `rdsrepladmin` user, which Amazon RDS uses for replication, is also a reserved user. Starting with RDS for MariaDB version 12.3, you can't drop this account at any host.
+    
+    
+    mysql> DROP USER 'rdsrepladmin'@'host';
+    ERROR 1396 (HY000): Operation DROP USER failed for 'rdsrepladmin'@'host'
+