RDS IAM¶
PgDog supports obtaining temporary credentials from AWS IAM and using those to connect to RDS PostgreSQL (and Aurora) instances.
Configuration¶
To use RDS IAM authentication, configure it on each user in users.toml, for example:
How it works¶
Under the hood, PgDog is using the AWS RDS SDK to fetch credentials at runtime. The SDK can retrieve temporary credentials from the environment or from the EC2 IAM API. It will use the role assigned to the EC2 instance or Kubernetes pod to connect to RDS.
If you're deploying PgDog in Kubernetes using our Helm chart, you can assign the PgDog container an IAM role with the correct permissions, for example:
serviceAccount:
create: true
annotations:
eks.amazonaws.com/role-arn: "arn:aws:iam::123456789012:role/pgdog-role"
Client authentication¶
RDS IAM authentication is currently only supported for connections between PgDog and PostgreSQL. Clients need to continue using one of the supported authentication mechanisms, e.g., password auth.
To completely avoid using passwords for user authentication, take a look at mTLS.
Multiple roles¶
PgDog supports assuming different roles for each user in order to connect to RDS. This is common when deploying PgDog across different AWS accounts or regions.
For each user in users.toml, you can specify its IAM role (and optionally IAM region) as follows:
In order for this to work correctly, make sure the IAM role used to deploy PgDog has the correct Trust Policy to assume all roles specified in the configuration.