AWS redshift: Add Fetch/UseDeclareFetch ODBC options and SSL verify-full note
Summary
Documents new ODBC driver options Fetch and UseDeclareFetch for batched result retrieval, rewrites the StreamingCursorRows description to clarify memory behavior and precedence, and adds a note recommending verify-full for SSL connections.
Security assessment
The bulk of the change documents performance/memory tuning options (Fetch, UseDeclareFetch, StreamingCursorRows) with no security impact, but the added note explicitly recommends the strongest TLS verification mode (verify-full), which prevents man-in-the-middle/certificate-spoofing on ODBC connections. This is security best-practice guidance rather than a fix for a specific vulnerability, so it is security documentation at medium severity.
Evidence
We recommend using `verify-full` for SSL connections whenever possible.
Diff
diff --git a/redshift/latest/mgmt/odbc20-configuration-options.md b/redshift/latest/mgmt/odbc20-configuration-options.md index 4f38e68ce..8538a2d77 100644 --- a//redshift/latest/mgmt/odbc20-configuration-options.md +++ b//redshift/latest/mgmt/odbc20-configuration-options.md @@ -7 +7 @@ -AccessKeyIDapp_idApplicationNameapp_nameAuthProfileAuthTypeAutoCreateBoolsAsCharCaFileclient_idclient_ secretClusterIdcompressionDatabaseDatabaseMetadataCurrentDbOnlydbgroups_filterDriverDSNEnableTableTypesEndpointUrlForceLowercasegroup_federationhttps_proxy_hosthttps_proxy_passwordhttps_proxy_porthttps_proxy_usernameIAMidc_client_display_nameidc_regionidp_hostidp_portidp_response_timeoutidp_tenantidp_partitionidp_use_https_proxyInstanceProfileissuer_urlKeepAliveKeepAliveCountKeepAliveIntervalKeepAliveIdlelisten_portlogin_urlloginToRpLogLevelLogPathLoginTimeoutMaxLongVarcharSizeMaxVarcharSizeMin_TLSpartner_spidPassword | PWDplugin_namePort | PortNumberPrefer_PQpreferred_roleProfileprovider_nameProxyHostProxyPortProxyPwdProxyUidReadOnlyregionSecretAccessKeySessionTokenServer | HostName | Hostssl_insecureSSLModeStreamingCursorRowsStsConnectionTimeoutStsEndpointUrltokentoken_typeUID | User | LogonIDUseUnicodeweb_identity_token +AccessKeyIDapp_idApplicationNameapp_nameAuthProfileAuthTypeAutoCreateBoolsAsCharCaFileclient_idclient_ secretClusterIdcompressionDatabaseDatabaseMetadataCurrentDbOnlydbgroups_filterDriverDSNEnableTableTypesEndpointUrlFetchForceLowercasegroup_federationhttps_proxy_hosthttps_proxy_passwordhttps_proxy_porthttps_proxy_usernameIAMidc_client_display_nameidc_regionidp_hostidp_portidp_response_timeoutidp_tenantidp_partitionidp_use_https_proxyInstanceProfileissuer_urlKeepAliveKeepAliveCountKeepAliveIntervalKeepAliveIdlelisten_portlogin_urlloginToRpLogLevelLogPathLoginTimeoutMaxLongVarcharSizeMaxVarcharSizeMin_TLSpartner_spidPassword | PWDplugin_namePort | PortNumberPrefer_PQpreferred_roleProfileprovider_nameProxyHostProxyPortProxyPwdProxyUidReadOnlyregionSecretAccessKeySessionTokenServer | HostName | Hostssl_insecureSSLModeStreamingCursorRowsStsConnectionTimeoutStsEndpointUrltokentoken_typeUID | User | LogonIDUseDeclareFetchUseUnicodeweb_identity_token @@ -62,0 +63,2 @@ Following are descriptions for the options that you can specify for the Amazon R + * Fetch + @@ -172,0 +175,2 @@ Following are descriptions for the options that you can specify for the Amazon R + * UseDeclareFetch + @@ -505,0 +510,13 @@ This parameter is optional. +## Fetch + + * Default Value – 100 + + * Data Type – Integer + + + + +When Declare/Fetch mode is enabled, this option controls how many rows the driver retrieves per round-trip, letting you tune the balance between memory use and network overhead for your workload. A larger value fetches more rows at once, reducing the number of round-trips to the server at the cost of higher memory per fetch. A smaller value lowers memory use but increases how often the driver goes back to the server. It sets the number of rows the driver returns at a time when `UseDeclareFetch` is enabled. For more information, see UseDeclareFetch. + +This parameter is optional. + @@ -1353,0 +1371,4 @@ The SSL certificate verification mode to use when connecting to Amazon Redshift. +###### Note + +We recommend using `verify-full` for SSL connections whenever possible. + @@ -1365 +1386 @@ This parameter is optional. -The number of rows the driver fetches per batch when using streaming cursor mode. When set to a positive integer and the cursor type is forward-only, the driver reads rows from the server in batches of the specified size instead of loading the entire result set into memory. +Limits how many rows the driver holds in memory at one time for a forward-only cursor, so that large result sets don't have to load into memory all at once. @@ -1369 +1390,3 @@ Set the property to one of the following values: - * 0: Disabled. The driver loads the entire result set into memory (default). + * 0: The driver loads the entire result set into memory before returning rows to the application (default). Very large result sets can consume a large amount of memory. + + * Positive integer: For a forward-only cursor, the driver keeps only that many rows in memory at a time. It returns those rows to the application, releases them, and then fetches the next batch once the application has consumed the current one. @@ -1371 +1393,0 @@ Set the property to one of the following values: - * Positive integer: The number of rows per streaming batch. @@ -1374,0 +1397 @@ Set the property to one of the following values: +This option has no effect on scrollable cursors, which always use the in-memory behavior. Note that on Windows, the Amazon Redshift ODBC Driver DSN Setup dialog pre-populates this field with a value of 100. @@ -1380 +1403 @@ Streaming cursor mode requires a forward-only cursor. If the Client Side Cursor -This option replaces the `UseDeclareFetch` and `Fetch` (Cache Size) options from ODBC driver version 1.x. Unlike the previous server-side cursor approach, streaming cursor mode does not require transaction wrapping or multiple server round-trips. +`StreamingCursorRows` and `UseDeclareFetch` both batch results instead of loading the entire result set into memory. `UseDeclareFetch` uses a server-side cursor and generally delivers significantly higher throughput, so prefer it when fetch performance is your primary concern. `StreamingCursorRows` does not require transaction wrapping or a server-side cursor; choose it when those properties matter more than peak speed – a forward-only stream with a bounded memory footprint. If `UseDeclareFetch` is enabled, it takes priority and forces `StreamingCursorRows` to 0. For more information, see UseDeclareFetch. @@ -1460,0 +1484,24 @@ This parameter is required if you use database authentication. +## UseDeclareFetch + + * Default Value – 0 + + * Data Type – Boolean + + + + +When a query returns a result set too large to hold in memory, enabling this option lets the driver process it in fixed-size batches instead of buffering the entire result at once, keeping the client's memory footprint bounded and predictable regardless of how many rows the query returns. It is a boolean specifying whether the driver uses Declare/Fetch mode, returning a set number of rows at a time. To set the number of rows returned per batch, use the `Fetch` option. For more information, see Fetch. + + * 1 | TRUE: The driver uses Declare/Fetch mode and returns the number of rows specified by the `Fetch` option at a time. + + * 0 | FALSE: The driver returns the entire query result at once. + + + + +This parameter is optional. + +###### Note + +If `UseDeclareFetch` is enabled, the driver disables streaming cursor mode and overrides `StreamingCursorRows` to 0, regardless of the value set in your DSN or connection string. For more information, see StreamingCursorRows. +