Skip to main content

sqlalchemy-rdsiam

SQLAlchemy dialect to connect to Amazon RDS instances with IAM authentication.

The following are supported:

  • Amazon RDS PostgreSQL, with psycopg2.
  • Amazon RDS PostgreSQL, with asyncpg.

SQLAlchemy 1.3, 1.4 and 2.0 are supported.

Background

Amazon RDS is managed database service on AWS, which provides the ability to connect to database instances with IAM authentication instead of passwords. AWS SDKs or the AWS CLI can be used to generate a connection token, valid for 15 minutes, and based on an Amazon IAM identity.

With SQLAlchemy, it is possible to use IAM authentication using one of the following options:

Both options require modifying the codebase to either inject the event handler or the custom connection factory. With many open-source tools, this requires maintaining a fork. This repository provides a set of dialects which can be installed and used directly in any SQLAlchemy codebase instead.

Getting Started

  • Install the Python package:

    pip install sqlalchemy-rdsiam
    
  • Use a connection string with scheme corresponding to the target PostgreSQL library, and leave out the password. For instance:

    postgresql+psycopg2rdsiam://username@host/dbname
    postgresql+asyncpgrdsiam://username@host/dbname
    

    Note: if a password is provided, it will be ignored.

  • Run with an IAM identity that has IAM permissions to connect to the database. See IAM authentication.

Additional Configuration

AWS Region

The default region in the environment is used. To access a database in a different region without changing your environment, pass the query parameter aws_region_name in the connection string:

postgresql+psycopg2rdsiam://username@host/dbname?aws_region_name=us-east-2

Creating the Database If It Doesn't Exists

The dialect supports optionally creating the database upon connection if it doesn't exist. This is disabled by default. To create the database if it doesn't exist, set the query parameter create_db_if_not_exists to true:

postgresql+psycopg2rdsiam://username@host/dbname?create_db_if_not_exists=true

Note: the role used must have permissions to create databases.

Set sslrootcert to the Amazon RDS Certificate Bundle

Amazon RDS TLS certificates are signed by Amazon certificate authorities, and the sslrootcert PostgreSQL argument must be used in order to verify the certificate chain when connecting to the instance. In some cases, it can be useful to directly get the CA bundle along with the package for testing, or to streaming provisioning. To this end, the CA bundle is automatically downloaded when installing the Python package, and you can opt-in to use it directly.

Note: make sure this is in line with your security posture requirements first.

The package can directly set sslrootcert to the certificate bundle for all Amazon RDS regions. This is disabled by default. To do so, set the query parameter rds_sslrootcert to true:

postgresql+psycopg2rdsiam://username@host/dbname?rds_sslrootcert=true

You still need to set sslmode - for instance, with sslmode=verify-full:

postgresql+psycopg2rdsiam://username@host/dbname?rds_sslrootcert=true&sslmode=verify-full

See SSL Support for additional details.

Contributing

See Contributing.

License

See License.

Metadata

Release files for sqlalchemy-rdsiam 1.0.3

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for sqlalchemy-rdsiam 1.0.3
File Size Uploaded
sqlalchemy-rdsiam-1.0.3.tar.gz 18.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for sqlalchemy-rdsiam 1.0.3
File Interpreter ABI Platform
sqlalchemy_rdsiam-1.0.3-py2.py3-none-any.whl Python 2, Python 3 none any Details

Total release size: 116.1 kB

Release files / sqlalchemy-rdsiam-1.0.3.tar.gz

Download URL sqlalchemy-rdsiam-1.0.3.tar.gz
Size 18.2 kB
Tags Source
SHA-256 checksum
How to use checksums
66a66b9194a398117ea6f79bb451bcee8be57ff94d9d8f8690172bb1ecba93bf
BLAKE2b-256 checksum
How to use checksums
f8cc2fd5293e5d6030f7bdf0bbb91c510613ca99b6c90528012c7b61a6bdefc7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.11.6

Release files / sqlalchemy_rdsiam-1.0.3-py2.py3-none-any.whl

Download URL sqlalchemy_rdsiam-1.0.3-py2.py3-none-any.whl
Size 97.9 kB
Tags Python 2 Python 3
SHA-256 checksum
How to use checksums
8e6f4da97e27878742044decb01290f500f13220cc4e9f54c0cc5837eb7f17bf
BLAKE2b-256 checksum
How to use checksums
31a48ea5067a84d7d52a771a44dff7d59055ef5de9631490918214540a295b9b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/4.0.2 CPython/3.11.6

Release history Release notifications | RSS feed

This release

1.0.3 This release

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page