AWS redshift: Redshift COPY authorization: drop key/CREDENTIALS auth, add SESSION
Summary
Removes documentation for the deprecated ACCESS_KEY_ID/SECRET_ACCESS_KEY, SESSION_TOKEN, and CREDENTIALS authorization methods for the COPY command, and adds a new IAM_ROLE 'SESSION' option that uses the caller's IAM-federated session credentials instead of an assumed cluster IAM role.
Security assessment
No CVE, advisory, or specific vulnerability is cited; the change is documentation hygiene that removes guidance for plain-text key/token and CREDENTIALS authorization (previously flagged as 'not recommended') and documents the SESSION-based federated-identity path with a note that it cannot be combined with other authorization methods and does not require attaching a cluster IAM role. This documents secure authentication behavior (federated session reuse, IAM permissions reference) rather than fixing an identified incident, so it is security-documentation/hardening of medium security impact.
Evidence
+Use the `SESSION` keyword to load data using the credentials of your current IAM-federated session. This option is available only when you connect to Amazon Redshift with an IAM-federated identity.
Diff
diff --git a/redshift/latest/dg/copy-parameters-authorization.md b/redshift/latest/dg/copy-parameters-authorization.md index abe4d5f3d..9ebbf8dbc 100644 --- a//redshift/latest/dg/copy-parameters-authorization.md +++ b//redshift/latest/dg/copy-parameters-authorization.md @@ -7 +7 @@ -Using IAM_ROLEUsing ACCESS_KEY_ID and SECRET_ACCESS_KEYUsing CREDENTIALS +Using IAM_ROLE @@ -21 +20,0 @@ The following topics provide more details and examples of authentication options - * [Key-based access control](./copy-usage_notes-access-permissions.html#copy-usage_notes-access-key-based) @@ -25,2 +24 @@ The following topics provide more details and examples of authentication options - -Use one of the following to provide authorization for the COPY command: +Use the following to provide authorization for the COPY command: @@ -30,4 +27,0 @@ Use one of the following to provide authorization for the COPY command: - * Using the ACCESS_KEY_ID and SECRET_ACCESS_KEY parameters parameters - - * Using the CREDENTIALS parameter clause - @@ -43 +37 @@ Use the default keyword to have Amazon Redshift use the IAM role that is set as -Use the Amazon Resource Name (ARN) for an IAM role that your cluster uses for authentication and authorization. If you specify IAM_ROLE, you can't use ACCESS_KEY_ID and SECRET_ACCESS_KEY, SESSION_TOKEN, or CREDENTIALS. +Use the Amazon Resource Name (ARN) for an IAM role that your cluster uses for authentication and authorization. @@ -48 +42 @@ The following shows the syntax for the IAM_ROLE parameter. - IAM_ROLE { default | 'arn:aws:iam::<AWS account-id>:role/<role-name>' } + IAM_ROLE { default | 'SESSION' | 'arn:aws:iam::<AWS account-id>:role/<role-name>' } @@ -52 +46 @@ For more information, see [Role-based access control](./copy-usage_notes-access- -## Using the ACCESS_KEY_ID and SECRET_ACCESS_KEY parameters +### SESSION @@ -54,5 +48 @@ For more information, see [Role-based access control](./copy-usage_notes-access- -### ACCESS_KEY_ID, SECRET_ACCESS_KEY - -This authorization method is not recommended. - -###### Note +Use the `SESSION` keyword to load data using the credentials of your current IAM-federated session. This option is available only when you connect to Amazon Redshift with an IAM-federated identity. @@ -60 +50 @@ This authorization method is not recommended. -Instead of providing access credentials as plain text, we strongly recommend using role-based authentication by specifying the IAM_ROLE parameter. For more information, see [Role-based access control](./copy-usage_notes-access-permissions.html#copy-usage_notes-access-role-based). +With `SESSION`, Amazon Redshift uses the same Amazon S3 permissions that your federated identity already has. Amazon Redshift doesn't assume a cluster IAM role, so you don't need to attach one to the cluster or workgroup for this access. @@ -62 +52 @@ Instead of providing access credentials as plain text, we strongly recommend usi -### SESSION_TOKEN +When you specify `SESSION`, you can't combine it with any other authorization method. @@ -64 +54 @@ Instead of providing access credentials as plain text, we strongly recommend usi -The session token for use with temporary access credentials. When SESSION_TOKEN is specified, you must also use ACCESS_KEY_ID and SECRET_ACCESS_KEY to provide temporary access key credentials. If you specify SESSION_TOKEN you can't use IAM_ROLE or CREDENTIALS. For more information, see [Temporary security credentials](./copy-usage_notes-access-permissions.html#r_copy-temporary-security-credentials) in the IAM User Guide. +To load with `SESSION`, you must have the permissions listed in [IAM permissions for COPY, UNLOAD, and CREATE LIBRARY](./copy-usage_notes-access-permissions.html#copy-usage_notes-iam-permissions). @@ -68,66 +58 @@ The session token for use with temporary access credentials. When SESSION_TOKEN -Instead of creating temporary security credentials, we strongly recommend using role-based authentication. When you authorize using an IAM role, Amazon Redshift automatically creates temporary user credentials for each session. For more information, see [Role-based access control](./copy-usage_notes-access-permissions.html#copy-usage_notes-access-role-based). - -The following shows the syntax for the SESSION_TOKEN parameter with the ACCESS_KEY_ID and SECRET_ACCESS_KEY parameters. - - - ACCESS_KEY_ID '<access-key-id>' - SECRET_ACCESS_KEY '<secret-access-key>' - SESSION_TOKEN '<temporary-token>'; - -If you specify SESSION_TOKEN you can't use CREDENTIALS or IAM_ROLE. - -## Using the CREDENTIALS parameter - -### CREDENTIALS - -A clause that indicates the method your cluster will use when accessing other AWS resources that contain data files or manifest files. You can't use the CREDENTIALS parameter with IAM_ROLE or ACCESS_KEY_ID and SECRET_ACCESS_KEY. - -The following shows the syntax for the CREDENTIALS parameter. - - - [WITH] CREDENTIALS [AS] 'credentials-args' - -###### Note - -For increased flexibility, we recommend using the IAM_ROLE parameter instead of the CREDENTIALS parameter. - -Optionally, if the [ENCRYPTED](./copy-parameters-data-source-s3.html#copy-encrypted) parameter is used, the _credentials-args_ string also provides the encryption key. - -The _credentials-args_ string is case-sensitive and must not contain spaces. - -The keywords WITH and AS are optional and are ignored. - -You can specify either [role-based access control](./copy-usage_notes-access-permissions.html#copy-usage_notes-access-role-based.phrase) or [key-based access control](./copy-usage_notes-access-permissions.html#copy-usage_notes-access-key-based.phrase). In either case, the IAM role or user must have the permissions required to access the specified AWS resources. For more information, see [IAM permissions for COPY, UNLOAD, and CREATE LIBRARY](./copy-usage_notes-access-permissions.html#copy-usage_notes-iam-permissions). - -###### Note - -To safeguard your AWS credentials and protect sensitive data, we strongly recommend using role-based access control. - -To specify role-based access control, provide the _credentials-args_ string in the following format. - - - 'aws_iam_role=arn:aws:iam::<aws-account-id>:role/<role-name>' - -To use temporary token credentials, you must provide the temporary access key ID, the temporary secret access key, and the temporary token. The _credentials-args_ string is in the following format. - - - CREDENTIALS - 'aws_access_key_id=<temporary-access-key-id>;aws_secret_access_key=<temporary-secret-access-key>;token=<temporary-token>' - -A COPY command using role-based access control with temporary credentials would resemble the following sample statement: - - - COPY customer FROM 's3://amzn-s3-demo-bucket/mydata' - CREDENTIALS - 'aws_access_key_id=<temporary-access-key-id>;aws_secret_access_key=<temporary-secret-access-key-id>;token=<temporary-token>' - -For more information, see [Temporary security credentials](./copy-usage_notes-access-permissions.html#r_copy-temporary-security-credentials). - -If the [ENCRYPTED](./copy-parameters-data-source-s3.html#copy-encrypted) parameter is used, the _credentials-args_ string is in the following format, where `<root-key>` is the value of the root key that was used to encrypt the files. - - - CREDENTIALS - '<credentials-args>;master_symmetric_key=<root-key>' - -A COPY command using role-based access control with an encryption key would resemble the following sample statement: - +`SESSION` isn't supported for auto-copy jobs. An auto-copy job runs asynchronously and can't access your federated session credentials, so it requires an IAM role. For more information, see [COPY JOB](./r_COPY-JOB.html). @@ -135,3 +60 @@ A COPY command using role-based access control with an encryption key would rese - COPY customer FROM 's3://amzn-s3-demo-bucket/mydata' - CREDENTIALS - 'aws_iam_role=arn:aws:iam::<account-id>:role/<role-name>;master_symmetric_key=<root-key>' +For an example of configuring a federated identity, see [Using a federated identity to manage Amazon Redshift access to local resources and Amazon Redshift Spectrum external tables](https://docs.aws.amazon.com/redshift/latest/mgmt/authorization-fas-spectrum.html).