- Newest
- Most votes
- Most comments
In order to establish a Glue connection from Account A (Glue service) to Redshift Cluster in Account B, you can follow these steps:
- In Account A, edit the rules of Security group "SG-A" to allow all traffic from itself and from the VPC-B (by providing its CDIR) as shown below:
Type | Protocol | Port Range | Source | Description
All Traffic | ALL | ALL | 10.0.0.0/16 | Allow traffic from VPC-B
All Traffic | ALL | ALL | SG-A | Self referencing SG 2
- In Acount B, edit the rules of Redshift security group "SG-B" to allow all traffic from VPC-A similar to below:
Type | Protocol | Port Range | Source | Description
All Traffic | ALL | ALL | 172.31.0.0/16 | Allow traffic from VPC-A
All Traffic | ALL | ALL | SG-B | Self referencing SG
-
Establish a cross-account VPC peering connection between VPC-A and VPC-B as per the instructions in this document http://docs.aws.amazon.com/AmazonVPC/latest/PeeringGuide/create-vpc-peering-connection.html#create-vpc-peering-connection-remote
-
After peering connection is setup properly, please make sure that route tables on both VPC's "VPC-A" and VPC-B" have a route between through them via PCX. For example, on subnet "Subnet-A", your route should look similar to:
Destination | Target
10.0.0.0/16 | pcx-xxxxxxx (your Peering connection_-ID)
- Similarly Redshift's Subnet route table should looks as:
Destination | Target
172.31.0.0/16 | pcx-xxxxxxx (your Peering connection_-ID)
-
Make sure Redshift cluster in Account B "publicly accessible" field is set to "No" as VPC-A and VPC-B can only tal with private. [In case public ip connections are enabled for the Redshift cluster you need to edit the Peering connections of the account where your Redshift cluster is to Allow accepter VPC to resolve DNS of requester VPC hosts to private IP]
-
Now the networking setup is complete, please add a new connection in Glue in "Acc-A" with following properties: Connection Type:
JDBC JDBC URL: <jdbc url of the redshift-cluster in Acc-B>
Username: <user-name of the redsfhit cluster in Acc-B>
Password: <password of the master user of redsfhit cluster in Acc-B>
VPC : VPC-A
Subnet: Subnet-A
Security Group: SG-A
- Test the connection and verify if it is setup successfully
Relevant content
- asked 2 years ago
- asked a year ago
- asked 2 years ago
- Accepted Answerasked a year ago
- AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated 10 months ago
Thank you! These steps worked.