AWS redshift: Redshift COPY docs drop key-based auth, promote IAM role temporary credentials
Summary
Removes the 'Key-based access control' section and detailed instructions for supplying plain-text access key ID/secret access key (and manual temporary credentials) for COPY/UNLOAD, consolidating guidance on role-based access control and IAM roles that automatically use temporary session credentials.
Security assessment
The change removes documentation encouraging plain-text long-lived access keys and steers users toward IAM roles with short-lived, auto-refreshed temporary credentials, reducing credential-leakage risk. It is a best-practice/hardening documentation update rather than a fix for a specific vulnerability or incident.
Evidence
+When you use role-based access control, Amazon Redshift automatically uses temporary security credentials on your behalf. Temporary security credentials provide enhanced security because they have short lifespans and can't be reused after they expire.
Diff
diff --git a/redshift/latest/dg/copy-usage_notes-access-permissions.md b/redshift/latest/dg/copy-usage_notes-access-permissions.md index 1eea66937..9dff42ecc 100644 --- a//redshift/latest/dg/copy-usage_notes-access-permissions.md +++ b//redshift/latest/dg/copy-usage_notes-access-permissions.md @@ -7 +7 @@ -Role-based access controlKey-based access controlIAM permissions +Role-based access controlTemporary security credentialsIAM permissions @@ -15 +15 @@ To move data between your cluster and another AWS resource, such as Amazon S3, A -To get authorization to access the resource, your cluster must be authenticated. You can choose either of the following authentication methods: +To get authorization to access the resource, your cluster must be authenticated using the following authentication method: @@ -19,2 +18,0 @@ To get authorization to access the resource, your cluster must be authenticated. - * Key-based access control – For key-based access control, you provide the AWS access credentials (access key ID and secret access key) for a user as plain text. - @@ -38 +36 @@ Role-based authentication delivers the following benefits: - * Your cluster obtains temporary session credentials at run time and refreshes the credentials as needed until the operation completes. If you use key-based temporary credentials, the operation fails if the temporary credentials expire before it completes. + * Your cluster obtains temporary session credentials at run time and refreshes the credentials as needed until the operation completes. @@ -49 +47 @@ You can add a role to a cluster or view the roles associated with a cluster by u -When you create an IAM role, IAM returns an Amazon Resource Name (ARN) for the role. To specify an IAM role, provide the role ARN with either the [Using the IAM_ROLE parameter](./copy-parameters-authorization.html#copy-iam-role) parameter or the [Using the CREDENTIALS parameter](./copy-parameters-authorization.html#copy-credentials) parameter. +When you create an IAM role, IAM returns an Amazon Resource Name (ARN) for the role. To specify an IAM role, provide the role ARN with the [Using the IAM_ROLE parameter](./copy-parameters-authorization.html#copy-iam-role) parameter. @@ -62,7 +59,0 @@ The following COPY command example uses the IAM_ROLE parameter with the ARN in t -The following COPY command example uses the CREDENTIALS parameter to specify the IAM role. - - - copy customer from 's3://amzn-s3-demo-bucket/mydata' - credentials - 'aws_iam_role=arn:aws:iam::0123456789012:role/MyRedshiftRole'; - @@ -71,77 +62 @@ In addition, a superuser can grant the ASSUMEROLE privilege to database users an -## Key-based access control - -With key-based access control, you provide the access key ID and secret access key for an IAM user that is authorized to access the AWS resources that contain the data. You can use either the [Using the ACCESS_KEY_ID and SECRET_ACCESS_KEY parameters](./copy-parameters-authorization.html#copy-access-key-id) parameters together or the [Using the CREDENTIALS parameter](./copy-parameters-authorization.html#copy-credentials) parameter. - -###### Note - -We strongly recommend using an IAM role for authentication instead of supplying a plain-text access key ID and secret access key. If you choose key-based access control, never use your AWS account (root) credentials. Always create an IAM user and provide that user's access key ID and secret access key. For steps to create an IAM user, see [Creating an IAM User in Your AWS Account](https://docs.aws.amazon.com/IAM/latest/UserGuide/id_users_create.html). - -To authenticate using ACCESS_KEY_ID and SECRET_ACCESS_KEY, replace `<access-key-id>` and `<secret-access-key>` with an authorized user's access key ID and full secret access key as shown following. - - - ACCESS_KEY_ID '<access-key-id>' - SECRET_ACCESS_KEY '<secret-access-key>'; - -To authenticate using the CREDENTIALS parameter, replace `<access-key-id>` and `<secret-access-key>` with an authorized user's access key ID and full secret access key as shown following. - - - CREDENTIALS - 'aws_access_key_id=<access-key-id>;aws_secret_access_key=<secret-access-key>'; - -The IAM user must have, at a minimum, the permissions listed in IAM permissions for COPY, UNLOAD, and CREATE LIBRARY. - -### Temporary security credentials - -If you are using key-based access control, you can further limit the access users have to your data by using temporary security credentials. Role-based authentication automatically uses temporary credentials. - -###### Note - -We strongly recommend using role-based access control instead of creating temporary credentials and providing access key ID and secret access key as plain text. Role-based access control automatically uses temporary credentials. - -Temporary security credentials provide enhanced security because they have short lifespans and can't be reused after they expire. The access key ID and secret access key generated with the token can't be used without the token, and a user who has these temporary security credentials can access your resources only until the credentials expire. - -To grant users temporary access to your resources, you call AWS Security Token Service (AWS STS) API operations. The AWS STS API operations return temporary security credentials consisting of a security token, an access key ID, and a secret access key. You issue the temporary security credentials to the users who need temporary access to your resources. These users can be existing IAM users, or they can be non-AWS users. For more information about creating temporary security credentials, see [Using Temporary Security Credentials](https://docs.aws.amazon.com/STS/latest/UsingSTS/Welcome.html) in the IAM User Guide. - -You can use either the [Using the ACCESS_KEY_ID and SECRET_ACCESS_KEY parameters](./copy-parameters-authorization.html#copy-access-key-id) parameters together with the [SESSION_TOKEN](./copy-parameters-authorization.html#copy-token) parameter or the [Using the CREDENTIALS parameter](./copy-parameters-authorization.html#copy-credentials) parameter. You must also supply the access key ID and secret access key that were provided with the token. - -To authenticate using ACCESS_KEY_ID, SECRET_ACCESS_KEY, and SESSION_TOKEN, replace `<temporary-access-key-id>`, `<temporary-secret-access-key>`, and `<temporary-token>` as shown following. - - - ACCESS_KEY_ID '<temporary-access-key-id>' - SECRET_ACCESS_KEY '<temporary-secret-access-key>' - SESSION_TOKEN '<temporary-token>'; - -To authenticate using CREDENTIALS, include `session_token=`<temporary-token>`` in the credentials string as shown following. - - - CREDENTIALS - 'aws_access_key_id=<temporary-access-key-id>;aws_secret_access_key=<temporary-secret-access-key>;session_token=<temporary-token>'; - -The following example shows a COPY command with temporary security credentials. - - - copy table-name - from 's3://objectpath' - access_key_id '<temporary-access-key-id>' - secret_access_key '<temporary-secret-access-key>' - session_token '<temporary-token>'; - -The following example loads the LISTING table with temporary credentials and file encryption. - - - copy listing - from 's3://amzn-s3-demo-bucket/data/listings_pipe.txt' - access_key_id '<temporary-access-key-id>' - secret_access_key '<temporary-secret-access-key>' - session_token '<temporary-token>' - master_symmetric_key '<root-key>' - encrypted; - -The following example loads the LISTING table using the CREDENTIALS parameter with temporary credentials and file encryption. - - - copy listing - from 's3://amzn-s3-demo-bucket/data/listings_pipe.txt' - credentials - 'aws_access_key_id=<temporary-access-key-id>;aws_secret_access_key=<temporary-secret-access-key>;session_token=<temporary-token>;master_symmetric_key=<root-key>' - encrypted; +## Temporary security credentials @@ -149 +64 @@ The following example loads the LISTING table using the CREDENTIALS parameter wi -###### Important +When you use role-based access control, Amazon Redshift automatically uses temporary security credentials on your behalf. Temporary security credentials provide enhanced security because they have short lifespans and can't be reused after they expire. @@ -151 +66 @@ The following example loads the LISTING table using the CREDENTIALS parameter wi -The temporary security credentials must be valid for the entire duration of the COPY or UNLOAD operation. If the temporary security credentials expire during the operation, the command fails and the transaction is rolled back. For example, if temporary security credentials expire after 15 minutes and the COPY operation requires one hour, the COPY operation fails before it completes. If you use role-based access, the temporary security credentials are automatically refreshed until the operation completes. +When you authorize using an IAM role, your cluster temporarily assumes the role and obtains temporary session credentials at run time. Your cluster refreshes these credentials as needed until the operation completes, so you don't need to provide or manage them yourself. For more information, see Role-based access control. @@ -155 +70 @@ The temporary security credentials must be valid for the entire duration of the -The IAM role or user referenced by the CREDENTIALS parameter must have, at a minimum, the following permissions: +The IAM role referenced by the IAM_ROLE parameter must have, at a minimum, the following permissions: