AWS redshift: Replace CREDENTIALS with IAM_ROLE in COPY JSON/AVRO example
Summary
The COPY command example for JSON/AVRO data formats was updated to use IAM_ROLE with an ARN instead of the CREDENTIALS 'credentials-args' parameter, promoting role-based access over embedded credentials.
Security assessment
The change replaces a generic credentials placeholder with an IAM role ARN, steering users toward role-based access control rather than passing raw credentials, which reduces credential exposure risk. It documents a security best practice but does not address a specific vulnerability.
Evidence
IAM_ROLE 'arn:aws:iam::<aws-account-id>:role/<role-name>'
Diff
diff --git a/redshift/latest/dg/copy-parameters-data-format.md b/redshift/latest/dg/copy-parameters-data-format.md index 4774a5a07..c0f76240e 100644 --- a//redshift/latest/dg/copy-parameters-data-format.md +++ b//redshift/latest/dg/copy-parameters-data-format.md @@ -315 +315 @@ To use a JSONPaths file, add the JSON or AVRO keyword to the COPY command. Speci - CREDENTIALS 'credentials-args' + IAM_ROLE 'arn:aws:iam::<aws-account-id>:role/<role-name>'