AWS redshift: Document IAM_ROLE 'SESSION' for federated identity COPY loads
Summary
Adds a paragraph explaining that IAM-federated identity users can load data using their current session credentials via IAM_ROLE 'SESSION' instead of assuming a cluster IAM role, with links to the SESSION parameter and a federated identity configuration example.
Security assessment
This documents an authentication/authorization mechanism (using federated session credentials instead of a long-lived cluster IAM role) for COPY loads, which is security-relevant guidance about credential handling, but it describes an existing feature rather than fixing a vulnerability.
Evidence
+If you connect with an IAM-federated identity, you can also load using the credentials of your current session by specifying `IAM_ROLE 'SESSION'`, rather than assuming a cluster IAM role. For more information, see [SESSION](./copy-parameters-authorization.html#copy-iam-role-session). For an example of configuring a federated identity, see [Using a federated identity to manage Amazon Redshift access to local resources and Amazon Redshift Spectrum external tables](https://docs.aws.amazon.com/redshift/latest/mgmt/authorization-fas-spectrum.html).
Diff
diff --git a/redshift/latest/dg/loading-data-access-permissions.md b/redshift/latest/dg/loading-data-access-permissions.md index e25720633..b686d7dca 100644 --- a//redshift/latest/dg/loading-data-access-permissions.md +++ b//redshift/latest/dg/loading-data-access-permissions.md @@ -36,0 +37,2 @@ The AWS user must have, at a minimum, the permissions listed in [IAM permissions +If you connect with an IAM-federated identity, you can also load using the credentials of your current session by specifying `IAM_ROLE 'SESSION'`, rather than assuming a cluster IAM role. For more information, see [SESSION](./copy-parameters-authorization.html#copy-iam-role-session). For an example of configuring a federated identity, see [Using a federated identity to manage Amazon Redshift access to local resources and Amazon Redshift Spectrum external tables](https://docs.aws.amazon.com/redshift/latest/mgmt/authorization-fas-spectrum.html). +