AWS redshift: UNLOAD: add IAM_ROLE SESSION keyword for federated identity
Summary
Adds the 'SESSION' value to the IAM_ROLE syntax and documents that it unloads data using the current IAM-federated session's credentials without assuming a cluster role. Also removes/relaxes previous restrictions tying IAM_ROLE and CREDENTIALS to KMS_KEY_ID, and updates the authentication guidance to point to IAM_ROLE.
Security assessment
The diff introduces a new authentication/authorization option (SESSION) that lets UNLOAD use the permissions of the caller's IAM-federated session and explicitly avoids assuming a cluster IAM role, while also relaxing old combinations with CREDENTIALS/KMS_KEY_ID. This documents identity/credential handling and least-privilege authorization behavior, but there is no evidence it fixes a specific vulnerability or incident.
Evidence
IAM_ROLE { default | 'SESSION' | 'arn:aws:iam::<AWS account-id-1>:role/<role-name>[,arn:aws:iam::<AWS account-id-2>:role/<role-name>][,...]' }
Diff
diff --git a/redshift/latest/dg/r_UNLOAD.md b/redshift/latest/dg/r_UNLOAD.md index 30ced9693..2d918d3fc 100644 --- a//redshift/latest/dg/r_UNLOAD.md +++ b//redshift/latest/dg/r_UNLOAD.md @@ -50 +50 @@ To apply least-privilege permissions, follow these recommendations to only grant - IAM_ROLE { default | 'arn:aws:iam::<AWS account-id-1>:role/<role-name>[,arn:aws:iam::<AWS account-id-2>:role/<role-name>][,...]' } + IAM_ROLE { default | 'SESSION' | 'arn:aws:iam::<AWS account-id-1>:role/<role-name>[,arn:aws:iam::<AWS account-id-2>:role/<role-name>][,...]' } @@ -121 +121 @@ The UNLOAD command needs authorization to write data to Amazon S3. The UNLOAD co -IAM_ROLE { default | 'arn:aws:iam::`<AWS account-id-1>`:role/`<role-name>`' +IAM_ROLE { default | 'SESSION' | 'arn:aws:iam::`<AWS account-id-1>`:role/`<role-name>`' } @@ -126 +126,9 @@ Use the default keyword to have Amazon Redshift use the IAM role that is set as -Use the Amazon Resource Name (ARN) for an IAM role that your cluster uses for authentication and authorization. If you specify IAM_ROLE, you can't use ACCESS_KEY_ID and SECRET_ACCESS_KEY, SESSION_TOKEN, or CREDENTIALS. The IAM_ROLE can be chained. For more information, see [Chaining IAM roles](https://docs.aws.amazon.com/redshift/latest/mgmt/authorizing-redshift-service.html#authorizing-redshift-service-chaining-roles) in the _Amazon Redshift Management Guide_. +Use the Amazon Resource Name (ARN) for an IAM role that your cluster uses for authentication and authorization. The IAM_ROLE can be chained. For more information, see [Chaining IAM roles](https://docs.aws.amazon.com/redshift/latest/mgmt/authorizing-redshift-service.html#authorizing-redshift-service-chaining-roles) in the _Amazon Redshift Management Guide_. + +Use the `SESSION` keyword to unload data using the credentials of your current IAM-federated session. This option is available only when you connect to Amazon Redshift with an IAM-federated identity. + +With `SESSION`, Amazon Redshift uses the same Amazon S3 permissions that your federated identity already has. Amazon Redshift doesn't assume a cluster IAM role, so you don't need to attach one to the cluster or workgroup for this access. + +When you specify `SESSION`, you can't combine it with any other authorization method. + +To unload with `SESSION`, you must have the permissions listed in Required privileges and permissions. For an example of configuring a federated identity, see [Using a federated identity to manage Amazon Redshift access to local resources and Amazon Redshift Spectrum external tables](https://docs.aws.amazon.com/redshift/latest/mgmt/authorization-fas-spectrum.html). @@ -199 +207 @@ Specifies that the output files on Amazon S3 are encrypted using Amazon S3 serve -For ENCRYPTED, you might want to unload to Amazon S3 using server-side encryption with an AWS KMS key (SSE-KMS). If so, use the KMS_KEY_ID parameter to provide the key ID. You can't use the [Using the CREDENTIALS parameter](./copy-parameters-authorization.html#copy-credentials) parameter with the KMS_KEY_ID parameter. If you run an UNLOAD command for data using KMS_KEY_ID, you can then do a COPY operation for the same data without specifying a key. +For ENCRYPTED, you might want to unload to Amazon S3 using server-side encryption with an AWS KMS key (SSE-KMS). If so, use the KMS_KEY_ID parameter to provide the key ID. If you run an UNLOAD command for data using KMS_KEY_ID, you can then do a COPY operation for the same data without specifying a key. @@ -201 +209 @@ For ENCRYPTED, you might want to unload to Amazon S3 using server-side encryptio -If ENCRYPTED AUTO is used, the UNLOAD command fetches the default AWS KMS encryption key on the target Amazon S3 bucket property and encrypts the files written to Amazon S3 with the AWS KMS key. If the bucket doesn't have the default AWS KMS encryption key, UNLOAD automatically creates encrypted files using Amazon Redshift server-side encryption with AWS-managed encryption keys (SSE-S3). You can't use this option with KMS_KEY_ID, MASTER_SYMMETRIC_KEY, or CREDENTIALS that contains master_symmetric_key. +If ENCRYPTED AUTO is used, the UNLOAD command fetches the default AWS KMS encryption key on the target Amazon S3 bucket property and encrypts the files written to Amazon S3 with the AWS KMS key. If the bucket doesn't have the default AWS KMS encryption key, UNLOAD automatically creates encrypted files using Amazon Redshift server-side encryption with AWS-managed encryption keys (SSE-S3). You can't use this option with KMS_KEY_ID or MASTER_SYMMETRIC_KEY. @@ -206 +214 @@ KMS_KEY_ID '_key-id_ ' -Specifies the key ID for an AWS Key Management Service (AWS KMS) key to be used to encrypt data files on Amazon S3. For more information, see [What is AWS Key Management Service?](https://docs.aws.amazon.com/kms/latest/developerguide/overview.html) If you specify KMS_KEY_ID, you must specify the ENCRYPTED parameter also. If you specify KMS_KEY_ID, you can't authenticate using the CREDENTIALS parameter. Instead, use either [Using the IAM_ROLE parameter](./copy-parameters-authorization.html#copy-iam-role) or [Using the ACCESS_KEY_ID and SECRET_ACCESS_KEY parameters](./copy-parameters-authorization.html#copy-access-key-id). +Specifies the key ID for an AWS Key Management Service (AWS KMS) key to be used to encrypt data files on Amazon S3. For more information, see [What is AWS Key Management Service?](https://docs.aws.amazon.com/kms/latest/developerguide/overview.html) If you specify KMS_KEY_ID, you must specify the ENCRYPTED parameter also. To authenticate, use the [Using the IAM_ROLE parameter](./copy-parameters-authorization.html#copy-iam-role) parameter.