DocumentDB - IAM Authentication?

0

Does DocumentDB support not only user/password but also IAM authentication? I see here: https://docs.aws.amazon.com/documentdb/latest/developerguide/security_iam_service-with-iam.html#security_iam_service-with-iam-id-based-policies But I'm looking for an example with IAM.

Thanks!

5 Answers
2
Accepted Answer

It's important to clarify that while IAM can be used to control access to Amazon DocumentDB resources and actions at the AWS level, it does not directly handle authentication inside the DocumentDB database itself. In other words, you can use IAM to control who can perform actions such as creating, deleting, or modifying DocumentDB clusters, but when it comes to connecting to a DocumentDB database instance and executing database operations, you still need to use traditional database authentication methods

profile picture
EXPERT
answered 10 months ago
profile picture
EXPERT
reviewed 9 months ago
profile picture
EXPERT
reviewed 10 months ago
1

I am not aware with an approach similar to RDS authentication via IAM role (https://repost.aws/knowledge-center/users-connect-rds-iam),so fir DocumentDB I think you ll have to use user/password for now.

profile picture
EXPERT
answered 10 months ago
profile picture
EXPERT
reviewed 10 months ago
profile picture
EXPERT
reviewed 10 months ago
1

Hi,

I would say that is not possible to authenticate using IAM.

According to the AWS documentation, in Amazon DocumentDB, users authenticate to a cluster in conjunction with a password.

On the other hand, the following AWS Knowledge Center page mentions that yoy might receive an "Authentication failed" error when you connect to your instance due to an incorrect password or incorrect username, but does not mention anything about IAM.

Finally, on the following StackOverflow question, they mention that there is no support at this time for IAM authentication for connections to DocumentDB.

profile picture
EXPERT
answered 10 months ago
profile picture
EXPERT
reviewed 10 months ago
profile picture
EXPERT
reviewed 10 months ago
1

Amazon DocumentDB recently introduced a new functionality and it now supports IAM database authentication. See the following resources for more info:
https://aws.amazon.com/about-aws/whats-new/2024/06/amazon-documentdb-iam-database-authentication https://docs.aws.amazon.com/documentdb/latest/developerguide/iam-identity-auth.html

AWS
EXPERT
answered 7 months ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions