# Certificate Authority support for RDS
mkdir -p $HOME/.postgresql
curl -L https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem -o $HOME/.postgresql/root.crt
# Certificate Authority support for AWS Certificate Manager used by RDS Proxy
curl -LO https://www.amazontrust.com/repository/AmazonRootCA1.pem
curl -LO https://www.amazontrust.com/repository/AmazonRootCA2.pem
curl -LO https://www.amazontrust.com/repository/AmazonRootCA3.pem
curl -LO https://www.amazontrust.com/repository/AmazonRootCA4.pem
cat AmazonRootCA1.pem >> $HOME/.postgresql/root.crt
cat AmazonRootCA2.pem >> $HOME/.postgresql/root.crt
cat AmazonRootCA3.pem >> $HOME/.postgresql/root.crt
cat AmazonRootCA4.pem >> $HOME/.postgresql/root.crt
curl -sSL https://install.python-poetry.org | python3 -
cd ~/git/infrastructure-blueprint-project/examples/python/test-auth
poetry install
CREATE USER <USERNAME> PASSWORD '<PASSWORD>';
Then test it:
poetry run python rds_auth_with_username_and_password.py \
--server <FQDN server address> \
--database <database name> \
--username <USERNAME> \
--password <PASSWORD>
poetry run python rds_auth_with_secrets_manager.py \
--server <FQDN server address> \
--database <database name> \
--secretsmanager "<secrets manager name>"
Create the IAM policies, roles and instance policy mentioned in IAM.md
CREATE USER little_helper;
GRANT rds_iam TO little_helper;
In order to find the <DBI_RESOURCE_ID>, you can run the following command:
aws rds describe-db-instances --query "DBInstances[*].[DBInstanceIdentifier,DbiResourceId]"
poetry run python rds_auth_with_iam.py \
--server <FQDN server address> \
--database <database name> \
--username little_helper
First read the previous chapter called Run test case for RDS auth with IAM, and do the following tasks from it:
Content type
Image
Digest
sha256:731acc77c…
Size
353.7 MB
Last updated
almost 3 years ago
docker pull dfdsdk/test-rds-iam-auth