Sign inSign up

dfdsdk/test-rds-iam-auth

By dfdsdk

•Updated almost 3 years ago

Image
0

1.4K

dfdsdk/test-rds-iam-auth repository overview

⁠Help

⁠Pre-recs on Linux and MacOs

# Certificate Authority support for RDS
mkdir -p $HOME/.postgresql
curl -L https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem -o $HOME/.postgresql/root.crt

# Certificate Authority support for AWS Certificate Manager used by RDS Proxy
curl -LO https://www.amazontrust.com/repository/AmazonRootCA1.pem
curl -LO https://www.amazontrust.com/repository/AmazonRootCA2.pem
curl -LO https://www.amazontrust.com/repository/AmazonRootCA3.pem
curl -LO https://www.amazontrust.com/repository/AmazonRootCA4.pem
cat AmazonRootCA1.pem >> $HOME/.postgresql/root.crt
cat AmazonRootCA2.pem >> $HOME/.postgresql/root.crt
cat AmazonRootCA3.pem >> $HOME/.postgresql/root.crt
cat AmazonRootCA4.pem >> $HOME/.postgresql/root.crt

curl -sSL https://install.python-poetry.org | python3 -

cd ~/git/infrastructure-blueprint-project/examples/python/test-auth
poetry install

⁠Run test case with PostgreSQL username and password

⁠Create a database user
CREATE USER <USERNAME> PASSWORD '<PASSWORD>';

Then test it:

poetry run python rds_auth_with_username_and_password.py \
	--server <FQDN server address> \
	--database <database name> \
	--username <USERNAME> \
	--password <PASSWORD>

⁠Run test case for RDS auth with Secrets Manager

poetry run python rds_auth_with_secrets_manager.py \
--server <FQDN server address> \
--database <database name> \
--secretsmanager "<secrets manager name>"

⁠Run test case for RDS auth with IAM

⁠Create IAM resources

Create the IAM policies, roles and instance policy mentioned in IAM.md

⁠Create database user for IAM auth
CREATE USER little_helper;
GRANT rds_iam TO little_helper;

In order to find the <DBI_RESOURCE_ID>, you can run the following command:

aws rds describe-db-instances --query "DBInstances[*].[DBInstanceIdentifier,DbiResourceId]"
  • Pick the db- value for the database you want to protect. If you would allow IAM access to all your databases, you can use * as a wildcard.
  • Instead of new database user little_helper you can also use a * wildcard in your policy to allow all database users that have been granted the rds_iam role.
poetry run python rds_auth_with_iam.py \
--server <FQDN server address> \
--database <database name> \
--username little_helper

⁠Run test case for RDS auth with IAM through IAM Roles for Service Accounts (IRSA)

First read the previous chapter called Run test case for RDS auth with IAM, and do the following tasks from it:

  • Create database user for IAM auth
  • Create IAM resources

Tag summary

Content type

Image

Digest

sha256:731acc77c…

Size

353.7 MB

Last updated

almost 3 years ago

docker pull dfdsdk/test-rds-iam-auth