AWS Security ChangesHomeSearch

AWS redshift: Add Iceberg materialized view refresh usage notes and limitations

Service: redshift · 2026-09-27 · Documentation medium

File: redshift/latest/dg/materialized-view-refresh-sql-command.md · Type: authz

Summary

Adds a new 'Iceberg materialized views' section covering required ALTER/SELECT permissions, snapshot-ID staleness detection, incremental refresh aggregate restrictions, optimistic concurrency control via AWS Glue Data Catalog, unsupported CASCADE/RESTRICT, and automatic full refresh on metadata integrity validation failure; plus a list of SQL elements that prevent incremental refresh.

Security assessment

The added notes document authorization requirements (caller needs ALTER, definer role needs SELECT on source tables) and an integrity-validation behavior that detects out-of-band modification of the materialized view, which is security-adjacent hardening guidance rather than a fix for a specific vulnerability.

Evidence

+  * If metadata integrity validation detects that the materialized view was modified outside of Amazon Redshift, Amazon Redshift automatically performs a full refresh to restore consistency.

Diff

diff --git a/redshift/latest/dg/materialized-view-refresh-sql-command.md b/redshift/latest/dg/materialized-view-refresh-sql-command.md
index 11824a619..90e065063 100644
--- a//redshift/latest/dg/materialized-view-refresh-sql-command.md
+++ b//redshift/latest/dg/materialized-view-refresh-sql-command.md
@@ -72,0 +73,28 @@ Some operations in Amazon Redshift interact with materialized views. Some of the
+### Iceberg materialized views
+
+For Iceberg materialized views created with USING ICEBERG, the following usage notes apply:
+
+  * The caller must have ALTER permission on the materialized view. The MV definer role (the IAM role recorded at create time) must have SELECT permission on all source tables.
+
+  * Amazon Redshift determines whether the materialized view is stale by comparing the current Iceberg snapshot IDs of source tables against the snapshot IDs recorded at the last refresh. If all snapshot IDs match, Amazon Redshift returns "Materialized view is up to date" without further processing.
+
+  * For incremental refresh, Amazon Redshift supports only COUNT and SUM aggregate functions. Materialized views using other aggregates (MIN, MAX, AVG) use full refresh.
+
+  * Multiple Amazon Redshift clusters can attempt to refresh the same Iceberg materialized view concurrently. Amazon Redshift uses optimistic concurrency control (OCC) through the AWS Glue Data Catalog to ensure that only one refresh succeeds. If another cluster completes the refresh first, the local operation returns success.
+
+  * CASCADE and RESTRICT options are not supported for Iceberg materialized views.
+
+  * If metadata integrity validation detects that the materialized view was modified outside of Amazon Redshift, Amazon Redshift automatically performs a full refresh to restore consistency.
+
+
+
+
+The following operations on base tables force a full recomputation on the next refresh:
+
+  * Source table snapshot expiration (when snapshots recorded at the last refresh are no longer available).
+
+  * Data modification on the materialized view by an external engine or tool.
+
+
+
+
@@ -136,0 +165,23 @@ For more information about materialized-view limitations, including the effect o
+For Iceberg materialized views, Amazon Redshift doesn't support incremental refresh for materialized views defined with any of the following SQL elements:
+
+  * OUTER JOIN (RIGHT, LEFT, or FULL)
+
+  * Set operations: INTERSECT, EXCEPT. UNION ALL is supported for incremental refresh.
+
+  * Aggregate functions other than COUNT and SUM
+
+  * DISTINCT aggregate functions, such as COUNT(DISTINCT) and SUM(DISTINCT)
+
+  * Window functions
+
+  * Subqueries
+
+  * GROUPING SETS, ROLLUP, CUBE
+
+  * DISTINCT
+
+
+
+
+When incremental refresh is not supported, Amazon Redshift automatically performs a full refresh.
+