AWS redshift: Update S3 COPY authorization to IAM role-based access
Summary
Removed references to key-based access control and CREDENTIALS parameter, added IAM_ROLE 'SESSION' for IAM-federated identities, and simplified MASTER_SYMMETRIC_KEY guidance to no longer mention CREDENTIALS.
Security assessment
The documentation drops key-based access control (raw credentials) in favor of IAM role-based access and adds support for federated session credentials, reducing long-lived credential usage. This is security best-practice guidance rather than a fix for a specific vulnerability.
Evidence
The COPY command needs authorization to access data in another AWS resource, including in Amazon S3, Amazon EMR, Amazon DynamoDB, and Amazon EC2. You can provide that authorization by referencing an AWS Identity and Access Management (IAM) role that is attached to your cluster (role-based access control). For Amazon S3 data, IAM-federated identities can use session credentials by specifying `IAM_ROLE 'SESSION'`.
Diff
diff --git a/redshift/latest/dg/copy-parameters-data-source-s3.md b/redshift/latest/dg/copy-parameters-data-source-s3.md index b14500efc..b71f528cb 100644 --- a//redshift/latest/dg/copy-parameters-data-source-s3.md +++ b//redshift/latest/dg/copy-parameters-data-source-s3.md @@ -126 +126 @@ _authorization_ -The COPY command needs authorization to access data in another AWS resource, including in Amazon S3, Amazon EMR, Amazon DynamoDB, and Amazon EC2. You can provide that authorization by referencing an AWS Identity and Access Management (IAM) role that is attached to your cluster (role-based access control) or by providing the access credentials for a user (key-based access control). For increased security and flexibility, we recommend using IAM role-based access control. For more information, see [Authorization parameters](./copy-parameters-authorization.html). +The COPY command needs authorization to access data in another AWS resource, including in Amazon S3, Amazon EMR, Amazon DynamoDB, and Amazon EC2. You can provide that authorization by referencing an AWS Identity and Access Management (IAM) role that is attached to your cluster (role-based access control). For Amazon S3 data, IAM-federated identities can use session credentials by specifying `IAM_ROLE 'SESSION'`. For more information, see [Authorization parameters](./copy-parameters-authorization.html). @@ -138 +138 @@ A clause that specifies that the input files on Amazon S3 are encrypted using cl -If you specify the ENCRYPTED parameter, you must also specify the MASTER_SYMMETRIC_KEY parameter or include the `master_symmetric_key` value in the [Using the CREDENTIALS parameter](./copy-parameters-authorization.html#copy-credentials) string. +If you specify the ENCRYPTED parameter, you must also specify the MASTER_SYMMETRIC_KEY parameter. @@ -147 +147 @@ MASTER_SYMMETRIC_KEY '_root_key_ ' -The root symmetric key that was used to encrypt data files on Amazon S3. If MASTER_SYMMETRIC_KEY is specified, the ENCRYPTED parameter must also be specified. MASTER_SYMMETRIC_KEY can't be used with the CREDENTIALS parameter. For more information, see [Loading encrypted data files from Amazon S3](./c_loading-encrypted-files.html). +The root symmetric key that was used to encrypt data files on Amazon S3. If MASTER_SYMMETRIC_KEY is specified, the ENCRYPTED parameter must also be specified. For more information, see [Loading encrypted data files from Amazon S3](./c_loading-encrypted-files.html).