AWS AmazonRDS: Added reserved users rdsproxyadmin and rdsrepladmin in MariaDB 12.3
Summary
Documented protection against dropping/modifying critical system accounts (rdsproxyadmin and rdsrepladmin) in MariaDB 12.3+.
Security assessment
Prevents accidental or malicious removal of system accounts required for RDS Proxy and replication, reducing privilege escalation risks.
Evidence
Starting with RDS for MariaDB version 12.3, `rdsproxyadmin` is also a reserved user.
Diff
diff --git a/AmazonRDS/latest/UserGuide/MariaDB.Concepts.UsersAndPrivileges.md b/AmazonRDS/latest/UserGuide/MariaDB.Concepts.UsersAndPrivileges.md index 24d2b2e62..302b42053 100644 --- a//AmazonRDS/latest/UserGuide/MariaDB.Concepts.UsersAndPrivileges.md +++ b//AmazonRDS/latest/UserGuide/MariaDB.Concepts.UsersAndPrivileges.md @@ -88,0 +89,17 @@ To provide management services for each DB instance, the `rdsadmin` user is crea +Starting with RDS for MariaDB version 12.3, `rdsproxyadmin` is also a reserved user. Amazon RDS creates this user the first time you register a DB instance as a target for a proxy. Attempting to create, drop, rename, or modify the `rdsproxyadmin` account at any host results in an error similar to the following: + + + mysql> DROP USER 'rdsproxyadmin'@'%'; + ERROR 1396 (HY000): Operation DROP USER failed for 'rdsproxyadmin'@'%' + + mysql> DROP USER 'rdsproxyadmin'@'host'; + ERROR 1396 (HY000): Operation DROP USER failed for 'rdsproxyadmin'@'host' + +For more information about the RDS Proxy monitoring user, see [Amazon RDS Proxy](./rds-proxy.html). + +The `rdsrepladmin` user, which Amazon RDS uses for replication, is also a reserved user. Starting with RDS for MariaDB version 12.3, you can't drop this account at any host. + + + mysql> DROP USER 'rdsrepladmin'@'host'; + ERROR 1396 (HY000): Operation DROP USER failed for 'rdsrepladmin'@'host' +