Comments (5)
Here are the full replication steps with an RDS PostgreSQL DB and psql:
- Logged in as master with psql:
-- Create two users for rotations
CREATE ROLE user1 WITH PASSWORD 'password' LOGIN;
CREATE ROLE user2 WITH PASSWORD 'password' LOGIN;
-- Allow these to create objects in the DB (ours is already setup with master)
GRANT master TO user1;
-- Grant role membership like lambda does
GRANT user1 TO user2;
- Logged in as user2:
-- Create schema and table as user2
CREATE SCHEMA test_schema;
CREATE TABLE test_schema.test_table ( column1 TEXT );
SELECT * FROM test_schema.test_table;
/****************
column1
---------
(0 rows)
****************/
-- View schemas (notice owner)
\dn+
/****************
List of schemas
Name | Owner | Access privileges | Description
------------------------------------------------------+------------+--------------------------+------------------------
public | master | master=UC/master +| standard public schema
| | =UC/master |
test_schema | user2 | |
(2 rows)
****************/
-- View tables (notice owner)
\dt *.*
/****************
List of relations
Schema | Name | Type | Owner
------------------------------------------------------+-------------------------+-------+------------
test_schema | test_table | table | user2
****************/
- Logged in as user1 (simulating rotation):
SELECT * FROM test_schema.test_table;
/****************
ERROR: permission denied for schema test_schema
LINE 1: SELECT * FROM test_schema.test_table;
****************/
from aws-secrets-manager-rotation-lambdas.
Thank you for opening this issue - we are looking into it.
from aws-secrets-manager-rotation-lambdas.
Sorry, I had talked this out with AWS support a while ago.
The issue stems from the two users not being read-only. If they have write permissions, the rotation lambda runs into this issue
This issue can likely be closed out, and maybe the rotation documentation updated to specify the users are supposed to be read-only
from aws-secrets-manager-rotation-lambdas.
We have been facing this exact same issue with our service users(who are not read-only) and have opened up a case with AWS support as well. They mentioned adding it as a feature request.
For now, as a workaround, we are forcefully setting the role of the current user on application startup.
Any chance of reopening this PR that was closed #57?
from aws-secrets-manager-rotation-lambdas.
We have addressed this issue with updating the documentation on when to use single or Multi User rotation strategy.
from aws-secrets-manager-rotation-lambdas.
Related Issues (20)
- Feature Request: Redshift Serverless Namespace admin user rotation HOT 2
- MySQL MultiUser lambda cannot rotate users with host different than default '%' HOT 3
- PostgreSQL SingleUser rotation, isn't working with RDS-Proxy HOT 1
- SecretsManagerRDSPostgreSQLRotationMultiUser doesn't support RDS Aurora Postgres HOT 1
- MultiUser rotations are incompatible with RDS Proxy HOT 12
- MySQL MultiUser Increase Username limit from 16 to 32 HOT 5
- secrets-manager automatic rotation for aws msk HOT 1
- SecretsManagerRDSMySQLRotationSingleUser error when require SSL HOT 4
- Name of IAM role not returned from AWS::SecretsManager::RotationSchedule HOT 1
- Aurora-mysql rotation fix HOT 1
- Update images to latest version of Python HOT 4
- Updating python enginefrom 3.7 to 3.11 Runtime.ImportModuleError HOT 3
- cx_Oracle has a major new release under a new name python-oracledb HOT 2
- MySQL and PostgreSQL support for aurora is inconsistent. HOT 2
- Secrets rotation fails for Oracle RDS with SSL or NNE HOT 4
- SqlServer rotation not respecting EXCLUDE_CHARACTERS HOT 6
- Cloud Formation Rotation type is missing for Elasticache Rotation Lambda HOT 1
- Getting cryptography' package is required while rotating secrets manager rds password HOT 5
- Include requirements.txt for each folder HOT 2
- SecretsManagerRDSMySQLRotationMultiUser through CloudFormation: KeyError 'masterarn' HOT 2
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from aws-secrets-manager-rotation-lambdas.