AWS Security ChangesHomeSearch

AWS redshift: Replace CREDENTIALS with IAM_ROLE in COPY JSON/AVRO example

Service: redshift · 2026-09-27 · Documentation medium

File: redshift/latest/dg/copy-parameters-data-format.md · Type: iam

Summary

The COPY command example for JSON/AVRO data formats was updated to use IAM_ROLE with an ARN instead of the CREDENTIALS 'credentials-args' parameter, promoting role-based access over embedded credentials.

Security assessment

The change replaces a generic credentials placeholder with an IAM role ARN, steering users toward role-based access control rather than passing raw credentials, which reduces credential exposure risk. It documents a security best practice but does not address a specific vulnerability.

Evidence

    IAM_ROLE 'arn:aws:iam::<aws-account-id>:role/<role-name>'

Diff

diff --git a/redshift/latest/dg/copy-parameters-data-format.md b/redshift/latest/dg/copy-parameters-data-format.md
index 4774a5a07..c0f76240e 100644
--- a//redshift/latest/dg/copy-parameters-data-format.md
+++ b//redshift/latest/dg/copy-parameters-data-format.md
@@ -315 +315 @@ To use a JSONPaths file, add the JSON or AVRO keyword to the COPY command. Speci
-    CREDENTIALS 'credentials-args' 
+    IAM_ROLE 'arn:aws:iam::<aws-account-id>:role/<role-name>'