<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Md. Mizanur Rahman</title>
    <description>The latest articles on DEV Community by Md. Mizanur Rahman (@mizaniftee).</description>
    <link>https://dev.to/mizaniftee</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1155430%2F064bc30a-645d-4512-b284-bc985cf735d8.jpg</url>
      <title>DEV Community: Md. Mizanur Rahman</title>
      <link>https://dev.to/mizaniftee</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/mizaniftee"/>
    <language>en</language>
    <item>
      <title>Data Export: Aurora-s3-Redshift</title>
      <dc:creator>Md. Mizanur Rahman</dc:creator>
      <pubDate>Wed, 23 Sep 2026 10:20:00 +0000</pubDate>
      <link>https://dev.to/mizaniftee/data-export-aurora-s3-redshift-32ei</link>
      <guid>https://dev.to/mizaniftee/data-export-aurora-s3-redshift-32ei</guid>
      <description>&lt;h1&gt;
  
  
  Exporting Data from Amazon Aurora MySQL to S3 and Loading It into Amazon Redshift
&lt;/h1&gt;

&lt;p&gt;This guide explains how to export data from Amazon Aurora MySQL into Amazon S3 and then import those CSV files into Amazon Redshift.&lt;/p&gt;

&lt;p&gt;The examples use generic testing resources:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;S3 bucket: &lt;code&gt;test-etl-bucket&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;IAM role: &lt;code&gt;test-etl-role&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Aurora user: &lt;code&gt;TestEtlUser&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;AWS account ID: &lt;code&gt;123456789012&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Aurora version: MySQL-compatible Aurora 3.x&lt;/li&gt;
&lt;li&gt;AWS Region: &lt;code&gt;us-east-1&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Architecture
&lt;/h2&gt;

&lt;p&gt;The data flow is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Aurora MySQL
    ↓ SELECT INTO OUTFILE S3
Amazon S3
    ↓ Redshift COPY
Amazon Redshift
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The IAM role is used by Aurora to write files to S3 and by Redshift to read those files.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 1: Create the IAM permissions policy
&lt;/h2&gt;

&lt;p&gt;Create an IAM policy with access to the testing bucket:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"Version"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"2012-10-17"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"Statement"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Sid"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"ListBucket"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Effect"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Allow"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Action"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="s2"&gt;"s3:ListBucket"&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Resource"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="s2"&gt;"arn:aws:s3:::test-etl-bucket"&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Sid"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"ReadWriteObjects"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Effect"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Allow"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Action"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="s2"&gt;"s3:GetObject"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="s2"&gt;"s3:PutObject"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="s2"&gt;"s3:AbortMultipartUpload"&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Resource"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="s2"&gt;"arn:aws:s3:::test-etl-bucket/*"&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Attach this policy to the IAM role:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;test-etl-role
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For stricter production security, separate roles are preferable:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Aurora export role with &lt;code&gt;PutObject&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;Redshift import role with &lt;code&gt;GetObject&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A shared role is acceptable for initial testing.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 2: Configure the IAM trust policy
&lt;/h2&gt;

&lt;p&gt;Use the following trust policy if the role needs to support Aurora, provisioned Redshift, and Redshift Serverless:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"Version"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"2012-10-17"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"Statement"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Effect"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"Allow"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Principal"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="nl"&gt;"Service"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
          &lt;/span&gt;&lt;span class="s2"&gt;"rds.amazonaws.com"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
          &lt;/span&gt;&lt;span class="s2"&gt;"redshift.amazonaws.com"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
          &lt;/span&gt;&lt;span class="s2"&gt;"redshift-serverless.amazonaws.com"&lt;/span&gt;&lt;span class="w"&gt;
        &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"Action"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"sts:AssumeRole"&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The role ARN in this example is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;arn:aws:iam::123456789012:role/test-etl-role
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If the S3 bucket uses a customer-managed KMS key, also grant the role &lt;code&gt;kms:Decrypt&lt;/code&gt; and &lt;code&gt;kms:GenerateDataKey&lt;/code&gt; as appropriate, and allow the role in the KMS key policy.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 3: Associate the role with Aurora
&lt;/h2&gt;

&lt;p&gt;Creating the IAM role is not enough. It must also be associated with the Aurora cluster.&lt;/p&gt;

&lt;p&gt;Open:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Amazon RDS
→ Databases
→ Select the Aurora cluster
→ Connectivity &amp;amp; security
→ Manage IAM roles
→ Add test-etl-role
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Wait until the role status becomes &lt;code&gt;Available&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Be sure to select the Aurora cluster, not only its writer instance.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 4: Configure the Aurora cluster parameter
&lt;/h2&gt;

&lt;p&gt;For Aurora MySQL version 3, set this DB cluster parameter:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;aws_default_s3_role
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Set its value to:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;arn:aws:iam::123456789012:role/test-etl-role
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The parameter must be configured in a custom DB cluster parameter group.&lt;/p&gt;

&lt;p&gt;Verify it from MySQL:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;SHOW&lt;/span&gt; &lt;span class="n"&gt;VARIABLES&lt;/span&gt; &lt;span class="k"&gt;LIKE&lt;/span&gt; &lt;span class="s1"&gt;'aws_default_s3_role'&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Expected result:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;arn:aws:iam::123456789012:role/test-etl-role
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Reboot the Aurora writer if the parameter change is waiting for a reboot.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 5: Grant the Aurora database role
&lt;/h2&gt;

&lt;p&gt;Grant S3 export access to the testing database user:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;GRANT&lt;/span&gt; &lt;span class="n"&gt;AWS_SELECT_S3_ACCESS&lt;/span&gt;
&lt;span class="k"&gt;TO&lt;/span&gt; &lt;span class="nv"&gt;`TestEtlUser`&lt;/span&gt;&lt;span class="o"&gt;@&lt;/span&gt;&lt;span class="nv"&gt;`%`&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Make all granted roles active automatically when the user reconnects:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;SET&lt;/span&gt; &lt;span class="k"&gt;DEFAULT&lt;/span&gt; &lt;span class="k"&gt;ROLE&lt;/span&gt; &lt;span class="k"&gt;ALL&lt;/span&gt;
&lt;span class="k"&gt;TO&lt;/span&gt; &lt;span class="nv"&gt;`TestEtlUser`&lt;/span&gt;&lt;span class="o"&gt;@&lt;/span&gt;&lt;span class="nv"&gt;`%`&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For the current MySQL session, activate the role immediately:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;SET&lt;/span&gt; &lt;span class="k"&gt;ROLE&lt;/span&gt; &lt;span class="k"&gt;ALL&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Verify it:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="k"&gt;CURRENT_USER&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt; &lt;span class="k"&gt;CURRENT_ROLE&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The result should include:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;`AWS_SELECT_S3_ACCESS`@`%`
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Application connection pools
&lt;/h3&gt;

&lt;p&gt;MySQL roles are session-specific unless they are configured as default roles. If the application uses a connection pool, &lt;code&gt;SET ROLE ALL&lt;/code&gt; and the export must run on the same physical connection.&lt;/p&gt;

&lt;p&gt;Example with Node.js:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;connection&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;pool&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;getConnection&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;

&lt;span class="k"&gt;try&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;connection&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;query&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;SET ROLE ALL&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

  &lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;roles&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;connection&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;query&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;`
    SELECT CURRENT_USER() AS current_user,
           CURRENT_ROLE() AS current_roles
  `&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

  &lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;roles&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

  &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nx"&gt;connection&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;query&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;`
    SELECT *
    FROM test_database.test_table
    INTO OUTFILE S3
      's3://test-etl-bucket/exports/test_table/run_001'
    FORMAT CSV HEADER
    OVERWRITE ON
  `&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;finally&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
  &lt;span class="nx"&gt;connection&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;release&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Do not run &lt;code&gt;SET ROLE ALL&lt;/code&gt; with one pooled connection and the export with another.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 6: Export Aurora data to S3
&lt;/h2&gt;

&lt;p&gt;Run:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;test_database&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;test_table&lt;/span&gt;
&lt;span class="k"&gt;INTO&lt;/span&gt; &lt;span class="n"&gt;OUTFILE&lt;/span&gt; &lt;span class="n"&gt;S3&lt;/span&gt;
  &lt;span class="s1"&gt;'s3://test-etl-bucket/exports/test_table/run_001'&lt;/span&gt;
&lt;span class="n"&gt;FORMAT&lt;/span&gt; &lt;span class="n"&gt;CSV&lt;/span&gt; &lt;span class="n"&gt;HEADER&lt;/span&gt;
&lt;span class="n"&gt;OVERWRITE&lt;/span&gt; &lt;span class="k"&gt;ON&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Aurora treats the S3 destination as an object prefix. It automatically creates files such as:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;exports/test_table/run_001.part_00000
exports/test_table/run_001.part_00001
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This naming is expected. The files contain CSV data even though their names do not end with &lt;code&gt;.csv&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Aurora does not provide an option to remove the &lt;code&gt;.part_00000&lt;/code&gt; suffix.&lt;/p&gt;

&lt;p&gt;If the selected dataset is empty, Aurora can produce a zero-byte object. Avoid including unwanted empty objects when loading data into Redshift.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 7: Associate the role with Redshift
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Provisioned Redshift
&lt;/h3&gt;

&lt;p&gt;Open:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Amazon Redshift
→ Provisioned clusters
→ Select the cluster
→ Properties
→ Cluster permissions
→ Manage IAM roles
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Associate:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;arn:aws:iam::123456789012:role/test-etl-role
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The equivalent AWS CLI command is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;aws redshift modify-cluster-iam-roles &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--cluster-identifier&lt;/span&gt; test-redshift-cluster &lt;span class="se"&gt;\&lt;/span&gt;
  &lt;span class="nt"&gt;--add-iam-roles&lt;/span&gt; &lt;span class="se"&gt;\&lt;/span&gt;
  arn:aws:iam::123456789012:role/test-etl-role
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Redshift Serverless
&lt;/h3&gt;

&lt;p&gt;Open:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Amazon Redshift
→ Redshift Serverless
→ Namespace configuration
→ Select the namespace
→ Security and encryption
→ Permissions
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Associate &lt;code&gt;test-etl-role&lt;/code&gt; with the namespace. It can optionally be configured as the default IAM role.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 8: Create the Redshift destination table
&lt;/h2&gt;

&lt;p&gt;The Redshift table must already exist before running &lt;code&gt;COPY&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Its column order and compatible data types must match the Aurora export:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;CREATE&lt;/span&gt; &lt;span class="k"&gt;SCHEMA&lt;/span&gt; &lt;span class="n"&gt;IF&lt;/span&gt; &lt;span class="k"&gt;NOT&lt;/span&gt; &lt;span class="k"&gt;EXISTS&lt;/span&gt; &lt;span class="n"&gt;staging&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="k"&gt;CREATE&lt;/span&gt; &lt;span class="k"&gt;TABLE&lt;/span&gt; &lt;span class="n"&gt;staging&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;test_table&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;
    &lt;span class="n"&gt;record_id&lt;/span&gt;       &lt;span class="nb"&gt;BIGINT&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
    &lt;span class="n"&gt;record_name&lt;/span&gt;     &lt;span class="nb"&gt;VARCHAR&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;500&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
    &lt;span class="n"&gt;record_status&lt;/span&gt;   &lt;span class="nb"&gt;VARCHAR&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;100&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
    &lt;span class="n"&gt;created_at&lt;/span&gt;      &lt;span class="nb"&gt;TIMESTAMP&lt;/span&gt;
&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Replace these example columns with the actual columns returned by the Aurora &lt;code&gt;SELECT&lt;/code&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 9: Validate the files without loading
&lt;/h2&gt;

&lt;p&gt;Use &lt;code&gt;NOLOAD&lt;/code&gt; to validate the CSV format and data types:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;COPY&lt;/span&gt; &lt;span class="n"&gt;staging&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;test_table&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="s1"&gt;'s3://test-etl-bucket/exports/test_table/run_001'&lt;/span&gt;
&lt;span class="n"&gt;IAM_ROLE&lt;/span&gt; &lt;span class="s1"&gt;'arn:aws:iam::123456789012:role/test-etl-role'&lt;/span&gt;
&lt;span class="n"&gt;FORMAT&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;CSV&lt;/span&gt;
&lt;span class="n"&gt;IGNOREHEADER&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;span class="n"&gt;REGION&lt;/span&gt; &lt;span class="s1"&gt;'us-east-1'&lt;/span&gt;
&lt;span class="n"&gt;NOLOAD&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Use &lt;code&gt;IGNOREHEADER 1&lt;/code&gt; only when the Aurora export used:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="n"&gt;FORMAT&lt;/span&gt; &lt;span class="n"&gt;CSV&lt;/span&gt; &lt;span class="n"&gt;HEADER&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If the export did not contain a header, remove &lt;code&gt;IGNOREHEADER 1&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;If S3 and Redshift are in the same Region, the &lt;code&gt;REGION&lt;/code&gt; option is optional. It is required when the bucket and Redshift are in different Regions.&lt;/p&gt;

&lt;h2&gt;
  
  
  Step 10: Load the data into Redshift
&lt;/h2&gt;

&lt;p&gt;After &lt;code&gt;NOLOAD&lt;/code&gt; succeeds, remove it and run the actual import:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;COPY&lt;/span&gt; &lt;span class="n"&gt;staging&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;test_table&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="s1"&gt;'s3://test-etl-bucket/exports/test_table/run_001'&lt;/span&gt;
&lt;span class="n"&gt;IAM_ROLE&lt;/span&gt; &lt;span class="s1"&gt;'arn:aws:iam::123456789012:role/test-etl-role'&lt;/span&gt;
&lt;span class="n"&gt;FORMAT&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;CSV&lt;/span&gt;
&lt;span class="n"&gt;IGNOREHEADER&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;span class="n"&gt;REGION&lt;/span&gt; &lt;span class="s1"&gt;'us-east-1'&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If the IAM role is configured as Redshift’s default role, the command can use:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="n"&gt;IAM_ROLE&lt;/span&gt; &lt;span class="k"&gt;default&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;COPY&lt;/span&gt; &lt;span class="n"&gt;staging&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;test_table&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="s1"&gt;'s3://test-etl-bucket/exports/test_table/run_001'&lt;/span&gt;
&lt;span class="n"&gt;IAM_ROLE&lt;/span&gt; &lt;span class="k"&gt;default&lt;/span&gt;
&lt;span class="n"&gt;FORMAT&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;CSV&lt;/span&gt;
&lt;span class="n"&gt;IGNOREHEADER&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Redshift loads every S3 object whose key matches the specified prefix.&lt;/p&gt;

&lt;p&gt;Therefore:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;s3://test-etl-bucket/exports/test_table/run_001
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;can load:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;run_001.part_00000
run_001.part_00001
run_001.part_00002
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Loading multiple files safely
&lt;/h2&gt;

&lt;p&gt;If every object under a folder has the same table structure, the complete folder can be loaded:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;COPY&lt;/span&gt; &lt;span class="n"&gt;staging&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;test_table&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="s1"&gt;'s3://test-etl-bucket/exports/test_table/'&lt;/span&gt;
&lt;span class="n"&gt;IAM_ROLE&lt;/span&gt; &lt;span class="k"&gt;default&lt;/span&gt;
&lt;span class="n"&gt;FORMAT&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;CSV&lt;/span&gt;
&lt;span class="n"&gt;IGNOREHEADER&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Do not load an entire folder when it contains:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Files for different destination tables&lt;/li&gt;
&lt;li&gt;Different column structures&lt;/li&gt;
&lt;li&gt;Temporary files&lt;/li&gt;
&lt;li&gt;Previous exports&lt;/li&gt;
&lt;li&gt;Unwanted zero-byte files&lt;/li&gt;
&lt;li&gt;Manifest files mixed with data files&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In these cases, use a specific prefix or a Redshift manifest.&lt;/p&gt;

&lt;p&gt;Example manifest:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="nl"&gt;"entries"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"url"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"s3://test-etl-bucket/exports/test_table/run_001.part_00000"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"mandatory"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;},&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"url"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"s3://test-etl-bucket/exports/test_table/run_001.part_00001"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
      &lt;/span&gt;&lt;span class="nl"&gt;"mandatory"&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="w"&gt;
    &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Load it with:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;COPY&lt;/span&gt; &lt;span class="n"&gt;staging&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;test_table&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="s1"&gt;'s3://test-etl-bucket/manifests/test_table_run_001.json'&lt;/span&gt;
&lt;span class="n"&gt;IAM_ROLE&lt;/span&gt; &lt;span class="k"&gt;default&lt;/span&gt;
&lt;span class="n"&gt;FORMAT&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;CSV&lt;/span&gt;
&lt;span class="n"&gt;IGNOREHEADER&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;span class="n"&gt;MANIFEST&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Avoiding duplicate data
&lt;/h2&gt;

&lt;p&gt;Redshift &lt;code&gt;COPY&lt;/code&gt; appends rows. It does not automatically replace existing rows or perform an upsert.&lt;/p&gt;

&lt;p&gt;For a complete refresh:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;BEGIN&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="k"&gt;TRUNCATE&lt;/span&gt; &lt;span class="k"&gt;TABLE&lt;/span&gt; &lt;span class="n"&gt;staging&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;test_table&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="k"&gt;COPY&lt;/span&gt; &lt;span class="n"&gt;staging&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;test_table&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="s1"&gt;'s3://test-etl-bucket/exports/test_table/run_001'&lt;/span&gt;
&lt;span class="n"&gt;IAM_ROLE&lt;/span&gt; &lt;span class="k"&gt;default&lt;/span&gt;
&lt;span class="n"&gt;FORMAT&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;CSV&lt;/span&gt;
&lt;span class="n"&gt;IGNOREHEADER&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="k"&gt;COMMIT&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For incremental imports, load into a staging table first and then use &lt;code&gt;MERGE&lt;/code&gt; based on the business key.&lt;/p&gt;

&lt;h2&gt;
  
  
  Common errors
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Aurora error 1227: SELECT INTO S3 privilege required
&lt;/h3&gt;

&lt;p&gt;Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Access denied; you need the SELECT INTO S3 privilege
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Cause:&lt;/p&gt;

&lt;p&gt;The &lt;code&gt;AWS_SELECT_S3_ACCESS&lt;/code&gt; role is granted but not active.&lt;/p&gt;

&lt;p&gt;Solution:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;SET&lt;/span&gt; &lt;span class="k"&gt;ROLE&lt;/span&gt; &lt;span class="k"&gt;ALL&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="k"&gt;CURRENT_ROLE&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For a permanent solution:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;SET&lt;/span&gt; &lt;span class="k"&gt;DEFAULT&lt;/span&gt; &lt;span class="k"&gt;ROLE&lt;/span&gt; &lt;span class="k"&gt;ALL&lt;/span&gt; &lt;span class="k"&gt;TO&lt;/span&gt; &lt;span class="nv"&gt;`TestEtlUser`&lt;/span&gt;&lt;span class="o"&gt;@&lt;/span&gt;&lt;span class="nv"&gt;`%`&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h3&gt;
  
  
  Aurora error 63985: Missing Credentials
&lt;/h3&gt;

&lt;p&gt;Example:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;S3 API returned error:
Missing Credentials: Cannot instantiate S3 Client
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Possible causes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;code&gt;aws_default_s3_role&lt;/code&gt; is empty or incorrect&lt;/li&gt;
&lt;li&gt;The role is not associated with the Aurora cluster&lt;/li&gt;
&lt;li&gt;The associated role is not in &lt;code&gt;Available&lt;/code&gt; status&lt;/li&gt;
&lt;li&gt;The IAM trust policy does not allow &lt;code&gt;rds.amazonaws.com&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;The parameter was changed but the writer still requires a reboot&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Export works in terminal but fails from application code
&lt;/h3&gt;

&lt;p&gt;Cause:&lt;/p&gt;

&lt;p&gt;The terminal session ran &lt;code&gt;SET ROLE ALL&lt;/code&gt;, but the application opened a different connection where the role was inactive.&lt;/p&gt;

&lt;p&gt;Solution:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Configure the AWS role as a default database role, or&lt;/li&gt;
&lt;li&gt;Execute &lt;code&gt;SET ROLE ALL&lt;/code&gt; on every new application connection&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Redshift S3 AccessDenied
&lt;/h3&gt;

&lt;p&gt;Check the following:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The role is associated with the correct Redshift cluster or namespace&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;COPY&lt;/code&gt; command uses the correct role ARN&lt;/li&gt;
&lt;li&gt;The role has &lt;code&gt;s3:ListBucket&lt;/code&gt; and &lt;code&gt;s3:GetObject&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;The bucket policy does not contain an explicit deny&lt;/li&gt;
&lt;li&gt;The KMS key policy allows the role when SSE-KMS is used&lt;/li&gt;
&lt;li&gt;Redshift Serverless trust includes &lt;code&gt;redshift-serverless.amazonaws.com&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Redshift data-format errors
&lt;/h3&gt;

&lt;p&gt;Validate first:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;COPY&lt;/span&gt; &lt;span class="n"&gt;staging&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;test_table&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="s1"&gt;'s3://test-etl-bucket/exports/test_table/run_001'&lt;/span&gt;
&lt;span class="n"&gt;IAM_ROLE&lt;/span&gt; &lt;span class="k"&gt;default&lt;/span&gt;
&lt;span class="n"&gt;FORMAT&lt;/span&gt; &lt;span class="k"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;CSV&lt;/span&gt;
&lt;span class="n"&gt;IGNOREHEADER&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;
&lt;span class="n"&gt;NOLOAD&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For provisioned Redshift, inspect recent load errors:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight sql"&gt;&lt;code&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;
&lt;span class="k"&gt;FROM&lt;/span&gt; &lt;span class="n"&gt;stl_load_errors&lt;/span&gt;
&lt;span class="k"&gt;ORDER&lt;/span&gt; &lt;span class="k"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;starttime&lt;/span&gt; &lt;span class="k"&gt;DESC&lt;/span&gt;
&lt;span class="k"&gt;LIMIT&lt;/span&gt; &lt;span class="mi"&gt;20&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Final checklist
&lt;/h2&gt;

&lt;p&gt;Before running the pipeline, confirm:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The IAM role has S3 read and write permissions&lt;/li&gt;
&lt;li&gt;The role trusts Aurora and the relevant Redshift service&lt;/li&gt;
&lt;li&gt;The role is associated with the Aurora cluster&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;aws_default_s3_role&lt;/code&gt; contains the correct role ARN&lt;/li&gt;
&lt;li&gt;
&lt;code&gt;AWS_SELECT_S3_ACCESS&lt;/code&gt; is active for &lt;code&gt;TestEtlUser&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;The role is associated with Redshift&lt;/li&gt;
&lt;li&gt;The Redshift destination table already exists&lt;/li&gt;
&lt;li&gt;The column order matches the CSV data&lt;/li&gt;
&lt;li&gt;Header handling is consistent&lt;/li&gt;
&lt;li&gt;The selected S3 prefix contains only the intended files&lt;/li&gt;
&lt;li&gt;Duplicate-load behavior has been considered&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Official references:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/AuroraMySQL.Integrating.SaveIntoS3.html" rel="noopener noreferrer"&gt;Aurora MySQL S3 export&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/redshift/latest/dg/copy-parameters-data-source-s3.html" rel="noopener noreferrer"&gt;Redshift COPY from S3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/redshift/latest/mgmt/copy-unload-iam-role.html" rel="noopener noreferrer"&gt;Redshift IAM-role authorization&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/redshift/latest/mgmt/serverless-security-other-services.html" rel="noopener noreferrer"&gt;Redshift Serverless permissions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>architecture</category>
      <category>aws</category>
      <category>database</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>Build Node.js app in Replit &amp; use s3 as static web hosting serving with CDN</title>
      <dc:creator>Md. Mizanur Rahman</dc:creator>
      <pubDate>Mon, 14 Jul 2025 12:19:36 +0000</pubDate>
      <link>https://dev.to/mizaniftee/build-nodejs-app-in-replit-use-s3-as-static-web-hosting-serving-with-cdn-4n83</link>
      <guid>https://dev.to/mizaniftee/build-nodejs-app-in-replit-use-s3-as-static-web-hosting-serving-with-cdn-4n83</guid>
      <description>&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fvya8qnklatuxvm1rgzr5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fvya8qnklatuxvm1rgzr5.png" alt=" " width="800" height="533"&gt;&lt;/a&gt;&lt;br&gt;
&lt;strong&gt;In this AI Era, there's lot of prompt module are available to ease our daily life. Among them i have found one good one which is 'replit'. link: &lt;a href="https://replit.com/" rel="noopener noreferrer"&gt;https://replit.com/&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I have developed my portfolio in replit. it's node.js app. i have given a prompt to develop like this and gave all kinds of information in replit.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9rl5zg78y5hxi1arype7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9rl5zg78y5hxi1arype7.png" alt=" " width="800" height="305"&gt;&lt;/a&gt;&lt;br&gt;
After building the project, i have downloaded the code and then build the application code locally.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;npm init -y&lt;br&gt;
npm run build&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Then i have created a S3 bucket and upload assets folder and index.html of that build project. [&lt;strong&gt;S3 has all public access blocked&lt;/strong&gt;]&lt;/p&gt;

&lt;p&gt;For static web hosting, i had to enable the "Static website hosting" from S3--&amp;gt; Properties.&lt;br&gt;
So, if that option is enabled then a weblink you will get and try to open it and found that your app is available on that link.[If public access enabled]&lt;/p&gt;

&lt;p&gt;Now the main part, CDN configuration. I have created an CDN with Default config.[CDN takes time to be created fully]&lt;br&gt;
I have configured altenate domain name with my domain 'mizaniftee.xyz'&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fjgr7ynbkbx8g7bjvin54.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fjgr7ynbkbx8g7bjvin54.png" alt=" " width="800" height="74"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Then i have configured the SSL from AWS ACM. Records were automatically added in my hosted zone.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;N.B: If you want to use CDN with your wildcard domain then it couldn't be added manually. like i wanted to forward mizaniftee.xyz to CDN URL but couldn't. here &lt;a href="http://www.mizaniftee.xyz" rel="noopener noreferrer"&gt;www.mizaniftee.xyz&lt;/a&gt; was doable&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;As i have set S3 as private, so i had to add some permission in s3 bucket by which CDN could access the files.&lt;br&gt;
going to s3--&amp;gt; Permissions then add below&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "AllowCloudFrontServicePrincipal",
            "Effect": "Allow",
            "Principal": {
                "Service": "cloudfront.amazonaws.com"
            },
            "Action": "s3:GetObject",
            "Resource": "arn:aws:s3:::s3_Bucket_name/*",
            "Condition": {
                "StringEquals": {
                    "AWS:SourceArn": "arn:aws:cloudfront::YOUR_ACCOUNT_ID:distribution/DISTRIBUTION_ID"
                }
            }
        }
    ]
}
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Now i could easily access my portfolio website with my domain which is serving through CDN to s3 bucket Files.&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>aws</category>
      <category>replit</category>
      <category>sre</category>
    </item>
    <item>
      <title>How to Create &amp; Setting Up IAM Identity Center</title>
      <dc:creator>Md. Mizanur Rahman</dc:creator>
      <pubDate>Wed, 27 Nov 2024 15:52:37 +0000</pubDate>
      <link>https://dev.to/mizaniftee/how-to-create-setting-up-iam-identity-center-4m1g</link>
      <guid>https://dev.to/mizaniftee/how-to-create-setting-up-iam-identity-center-4m1g</guid>
      <description>&lt;p&gt;IAM Identity Center is the AWS solution for connecting your workforce users to AWS managed application.&lt;br&gt;
Identity Center Permission Sets are basically templates of IAM roles that will be provisioned in the account. When you assign a permission set to an account, the role is created and a trust policy to handle the federation is configured automatically.&lt;br&gt;
It also supports SSO[Single Sign-On] as well as you could integrate 3rd party like AAD[Azure Active Directory] to this.&lt;/p&gt;

&lt;h3&gt;
  
  
  Getting Started:
&lt;/h3&gt;

&lt;p&gt;First Go to that account Console with &lt;a href="https://Account_Number.signin.aws.amazon.com/console" rel="noopener noreferrer"&gt;https://Account_Number.signin.aws.amazon.com/console&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Then Search &lt;strong&gt;IAM Identity Center&lt;/strong&gt; and Press on &lt;strong&gt;Enable&lt;/strong&gt;. You can Enable in any region as you wish.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;N.B- Though you have enabled IAM Identity Center, you could also use specific account console as you have used before. Like &lt;a href="https://Account_Number.signin.aws.amazon.com/console" rel="noopener noreferrer"&gt;https://Account_Number.signin.aws.amazon.com/console&lt;/a&gt; but for that you need to have IAM Role for that Or Root Account Holder.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F56wyk8obdxn2wmapefk9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F56wyk8obdxn2wmapefk9.png" alt=" " width="800" height="241"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After Enabling, Got Successful Message&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ft6pzan8c1qsgrw1h3fw0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Ft6pzan8c1qsgrw1h3fw0.png" alt=" " width="800" height="51"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now, Edit the Instance name as it will be showed when you want to access through &lt;em&gt;AWS Access Portal&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fzuf3pwcgogfidt1mqqnm.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fzuf3pwcgogfidt1mqqnm.png" alt=" " width="313" height="98"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;If you want to customize your access portal URL and provide the URL to the USER. Go to Dashboard&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fj95ovj9yxidl8u4abwmb.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fj95ovj9yxidl8u4abwmb.png" alt=" " width="800" height="257"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;So, Link will be like that &lt;code&gt;https://mizanzone.awsapps.com/start&lt;/code&gt;. And After login, we could see the &lt;strong&gt;Mizan tech Account&lt;/strong&gt; For that specific account.&lt;/p&gt;

&lt;h2&gt;
  
  
  Permission &amp;amp; Others:
&lt;/h2&gt;

&lt;p&gt;You need to create permissions sets. There are some predefined sets like below:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F8z0h60pmxyv6x69c97jf.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F8z0h60pmxyv6x69c97jf.png" alt=" " width="800" height="518"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fybb3zd6eshcn4p9cw42o.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fybb3zd6eshcn4p9cw42o.png" alt=" " width="311" height="202"&gt;&lt;/a&gt;&lt;br&gt;
&lt;code&gt;Here session is = aws access portal session after login.&lt;/code&gt;&lt;br&gt;
&lt;strong&gt;Relay State:&lt;/strong&gt; No need right now &lt;em&gt;[it will forward to that URL what is set in the section]&lt;/em&gt;&lt;br&gt;
You could set Custom Permission set there. Like only &lt;strong&gt;Ec2-admin/ S3-Access&lt;/strong&gt; as You want per requirements.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fn8h5ncfoztnh9v205cuz.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fn8h5ncfoztnh9v205cuz.png" alt=" " width="800" height="190"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;You will create groups and set users to that group.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fr55jx35x2ba9loqhjzcf.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fr55jx35x2ba9loqhjzcf.png" alt=" " width="800" height="153"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Now we will create users and assign to the required groups. Please create users with mail-wise for the company. So that anyone could use their mail as Username.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fscmh9oytuxyxyvzm64hh.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fscmh9oytuxyxyvzm64hh.png" alt=" " width="800" height="100"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After Creating the IAM Identity center, Root user will create another user to work with him in the same account or in the identity center.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;N.B: You could add multiple AWS Accounts under Same organization. Just need to send invite from AWS Organization page.After that, all the Accounts will be listed under IAM Identity Center AWS Account&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;So, You need to assign permission sets &amp;amp; Groups to the accounts of that AWS Organization. What Permission set and groups are added in the AWS Account, only those could access that account permission wise.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Flpisnjbnfnd9femb0cih.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Flpisnjbnfnd9femb0cih.png" alt=" " width="800" height="136"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;When we have multiple accounts that time all the accounts will be listed above.&lt;br&gt;
Now, we will use Access portal URL [&lt;code&gt;https://mizanzone.awsapps.com/start/&lt;/code&gt;] and after login, we will get views like that&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9t4e27ey0uckx69ags8d.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F9t4e27ey0uckx69ags8d.png" alt=" " width="403" height="589"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fuckiw0qb1vykl5tqdwhn.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fuckiw0qb1vykl5tqdwhn.png" alt=" " width="480" height="84"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;References:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/singlesignon/latest/userguide/get-set-up-for-idc.html" rel="noopener noreferrer"&gt;https://docs.aws.amazon.com/singlesignon/latest/userguide/get-set-up-for-idc.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://dev.to/aws-builders/setting-up-aws-iam-identity-center-as-an-identity-provider-for-confluence-2l8"&gt;https://dev.to/aws-builders/setting-up-aws-iam-identity-center-as-an-identity-provider-for-confluence-2l8&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=bVjwu1WN42I" rel="noopener noreferrer"&gt;https://www.youtube.com/watch?v=bVjwu1WN42I&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;

</description>
    </item>
    <item>
      <title>How to Update Aurora Global Database Version</title>
      <dc:creator>Md. Mizanur Rahman</dc:creator>
      <pubDate>Sun, 15 Sep 2024 16:09:32 +0000</pubDate>
      <link>https://dev.to/mizaniftee/how-to-update-aurora-global-database-version-flc</link>
      <guid>https://dev.to/mizaniftee/how-to-update-aurora-global-database-version-flc</guid>
      <description>&lt;p&gt;From time to time we need to update our database version to latest to get the new changes. it could be a major change or minor change.&lt;br&gt;
For minor changes, AWS has provided a option "Auto Minor Version Upgrade" feature for Single RDS, Multi AZ &amp;amp; Aurora single Cluster.&lt;br&gt;
But that feature doesn't apply to the following kinds of Aurora Global clusters:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Clusters that are part of an Aurora global database&lt;/li&gt;
&lt;li&gt;Clusters that have cross-Region replicas&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So, we need to follow some process to update that global DB.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;First, Remove all secondary Regions from the global cluster.&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Just Select the secondary cluster and go to “&lt;strong&gt;Actions&lt;/strong&gt;“&lt;br&gt;
So, that secondary cluster will be a regional cluster and a seperate cluster.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;Upgrade the engine version of the primary Region to desired version, as applicable from Portal or CLI or Terraform[any IAC]&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Now, if "&lt;strong&gt;Enable Deletion Protection&lt;/strong&gt;" is enabled then please disable that option for secondary cluster.&lt;br&gt;
Now delete that secondary region cluster/ you could use as another cluster if needed. if you don't delete then either you have to add with another DB identifier or you will get thise error.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fac35o55ix7674oojy5o2.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/cdn-cgi/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fac35o55ix7674oojy5o2.png" alt="Image description" width="571" height="37"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;After Deletion, please select the Global Database and go to "&lt;strong&gt;Actions&lt;/strong&gt;" and "select Add AWS Region". [&lt;strong&gt;check references no-3&lt;/strong&gt;]&lt;br&gt;
If you use Terraform code then run "&lt;strong&gt;terraform apply&lt;/strong&gt;" and it will take time to create those instances.&lt;/p&gt;

&lt;h2&gt;
  
  
  References:
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/aurora-global-database-managing.html#aurora-global-database-detaching" rel="noopener noreferrer"&gt;https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/aurora-global-database-managing.html#aurora-global-database-detaching&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/AuroraMySQL.Updates.Patching.html#modify-db-cluster-engine-version" rel="noopener noreferrer"&gt;https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/AuroraMySQL.Updates.Patching.html#modify-db-cluster-engine-version&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/aurora-global-database-getting-started.html#aurora-global-database-attaching" rel="noopener noreferrer"&gt;https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/aurora-global-database-getting-started.html#aurora-global-database-attaching&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://newsletter.simpleaws.dev/p/aurora-global-database-disaster-recovery-aws" rel="noopener noreferrer"&gt;https://newsletter.simpleaws.dev/p/aurora-global-database-disaster-recovery-aws&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;

</description>
    </item>
    <item>
      <title>AWS RDS Proxy For Aurora Global Database [MYSQL]</title>
      <dc:creator>Md. Mizanur Rahman</dc:creator>
      <pubDate>Wed, 17 Jul 2024 10:12:52 +0000</pubDate>
      <link>https://dev.to/mizaniftee/aws-rds-proxy-for-aurora-global-database-mysql-561l</link>
      <guid>https://dev.to/mizaniftee/aws-rds-proxy-for-aurora-global-database-mysql-561l</guid>
      <description>&lt;p&gt;Using Amazon RDS Proxy, you can allow your applications to pool and share database connections to improve their ability to scale.&lt;br&gt;
It does so in an active way first by understanding the database protocol. It then adjusts its behavior based on the SQL operations from your application and the result sets from the database.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Quotas/Limitation:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;you can have up to 20 proxies for each AWS account ID&lt;/li&gt;
&lt;li&gt;Each proxy has a default endpoint. You can also add up to 20 proxy endpoints for each proxy.&lt;/li&gt;
&lt;li&gt;Each proxy can have up to 200 associated Secrets Manager secrets&lt;/li&gt;
&lt;li&gt;RDS Proxy must be in the same virtual private cloud (VPC) as the database. The proxy can't be publicly accessible&lt;/li&gt;
&lt;li&gt;Each proxy can be associated with a single target DB cluster [For Primary need 1 and For Secondary Need another 1]&lt;/li&gt;
&lt;li&gt;can't use RDS Proxy with an RDS for MySQL DB instance that has the read_only parameter in its DB parameter group set to 1.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Transactions By RDS Proxy:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Connection reuse can happen after each individual statement when the Aurora MySQL autocommit setting is turned on.&lt;/li&gt;
&lt;li&gt;Conversely, when the autocommit setting is turned off, the first statement you issue in a session begins a new transaction. For example, suppose that you enter a sequence of SELECT, INSERT, UPDATE, and other data manipulation language (DML) statements. In this case, connection reuse doesn't happen until you issue a COMMIT, ROLLBACK, or otherwise end the transaction.&lt;/li&gt;
&lt;li&gt;Entering a data definition language (DDL) statement causes the transaction to end after that statement completes.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Failover:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Without RDS Proxy, a failover involves a brief outage. During DB failovers, RDS Proxy continues to accept connections at the same IP address and automatically directs connections to the new primary DB instance. [When Failover happens, the secondary cluster becomes primary]&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;When the database writer is unavailable, RDS Proxy queues up incoming requests.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;IP Address Capacity For RDS Proxy:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Aurora Global DB and RDS Proxy should be in same VPC should have a minimum of two subnets that are in different Availability Zones.&lt;br&gt;
Following are the recommended minimum numbers of IP addresses to leave free in subnets for proxy based on DB instance class sizes.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fri2s8vt0fmaxv0qq6jwv.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fri2s8vt0fmaxv0qq6jwv.png" alt="Image description"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;In this case, assume the following:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Aurora DB cluster has 1 writer instance of size db.r5.8xlarge and 1 reader instance of size db.r5.2xlarge.&lt;/li&gt;
&lt;li&gt;The proxy that's attached to this DB cluster has the default endpoint and 1 custom endpoint with the read-only role.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In this case, the proxy needs approximately 63 free IP addresses (45 for the writer instance, 15 for reader instance, and 3 for the additional custom endpoint).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Database Credentials in AWS Secrets:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;For each proxy that we will create, we will first use the Secrets Manager service to store sets of user name and password credentials. Need to create a separate Secrets Manager secret for each database user account that the proxy connects to on the Aurora DB cluster.&lt;/p&gt;

&lt;p&gt;To do this, you can use the setting Credentials for other database, Credentials for RDS database, or Other type of secrets.&lt;br&gt;
Fill in the appropriate values for the User name and Password fields, and values for any other required fields.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;{"username":"db_user",&lt;br&gt;
"password":"db_user_password"}&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;strong&gt;IAM Policy to access:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;After you create the secrets in Secrets Manager, you create an IAM policy that can access those secrets.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;You could create IAM Role automatically when you create the rds proxy.&lt;/li&gt;
&lt;li&gt;You could create policy first, then create role and add assign that role when creating the proxy&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;em&gt;Role Creation:&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F70nd187qcjcycult414a.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F70nd187qcjcycult414a.png" alt="Image description"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Futz9dt5kzr24quehx8bc.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Futz9dt5kzr24quehx8bc.png" alt="Image description"&gt;&lt;/a&gt;&lt;br&gt;
then go for "&lt;strong&gt;next&lt;/strong&gt;"&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Policy Creation:&lt;/em&gt;&lt;br&gt;
Use inline policy and add below&lt;/p&gt;

&lt;p&gt;&lt;code&gt;{&lt;br&gt;
    "Version": "2012-10-17",&lt;br&gt;
    "Statement": [&lt;br&gt;
        {&lt;br&gt;
            "Sid": "VisualEditor0",&lt;br&gt;
            "Effect": "Allow",&lt;br&gt;
            "Action": "secretsmanager:GetSecretValue",&lt;br&gt;
            "Resource": [&lt;br&gt;
                "arn:aws:secretsmanager:us-east-2:account_id:secret:secret_name_1",&lt;br&gt;
                "arn:aws:secretsmanager:us-east-2:account_id:secret:secret_name_2"&lt;br&gt;
            ]&lt;br&gt;
        },&lt;br&gt;
        {&lt;br&gt;
            "Sid": "VisualEditor1",&lt;br&gt;
            "Effect": "Allow",&lt;br&gt;
            "Action": "kms:Decrypt",&lt;br&gt;
            "Resource": "arn:aws:kms:us-east-2:account_id:key/key_id",&lt;br&gt;
            "Condition": {&lt;br&gt;
                "StringEquals": {&lt;br&gt;
                    "kms:ViaService": "secretsmanager.us-east-2.amazonaws.com"&lt;br&gt;
                }&lt;br&gt;
            }&lt;br&gt;
        }&lt;br&gt;
    ]&lt;br&gt;
}&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Configuration Points: [Main Points]&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;em&gt;Idle client connection timeout&lt;/em&gt;: Default time 1800s(30m) where a connection could be idle.A client connection is considered idle when the application doesn't submit a new request within the specified time after the previous request completed.&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;Connection pool maximum connections&lt;/em&gt;: Specify a value from 1 through 100. This setting represents the percentage of the max_connections value that RDS Proxy can use for its connections.&lt;/li&gt;
&lt;li&gt;Like our Prod DB max connection is 4000, so what percentage we will set , rds proxy will use that [percentage*4000]/100&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;Connection borrow timeout&lt;/em&gt;: If proxy use all available connection then can specify how long the proxy waits for a database connection to become available before returning a timeout error. We can specify a period up to a maximum of five minutes.&lt;/li&gt;
&lt;li&gt;
&lt;em&gt;VPC security group&lt;/em&gt;: must configure the Inbound rules to allow your applications to access the proxy. We must also configure the Outbound rules to allow traffic from our DB targets.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Endpoint for RDS Proxy:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Each proxy handles connections to a single Aurora DB cluster. If Global DB has a Primary &amp;amp; Secondary Cluster, so you need two RDS Proxy in this regard.&lt;/li&gt;
&lt;li&gt;Add Reader Proxy Endpoint in RDS Proxy will create a read endpoint that points to Aurora DB Cluster Reader.&lt;/li&gt;
&lt;li&gt;Default [Read/Write] Proxy endpoint works with Write instance&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fihfw6wrdwgz32k5j1a6m.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fihfw6wrdwgz32k5j1a6m.png" alt="Image description"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;You could connect directly to DB or through RDS Proxy, but if we connect with RDS Proxy then you need to create secrets for every user.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;COST:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;RDS Proxy pricing correlates to the number of vCPUs for each database instance in your Aurora cluster.&lt;br&gt;
If Aurora cluster that has a db.r6.large writer instance (2 vCPUs) and a db.r6.large reader instance (2 vCPUs $0.015 per vCPU-hour) &lt;br&gt;
So, Monthly bill → 2,880 vCPU-hours (4 vCPU x 24 hours x 30 days)==$43.20&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;References&lt;/strong&gt;:&lt;br&gt;
&lt;a href="https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/rds-proxy-network-prereqs.html" rel="noopener noreferrer"&gt;https://docs.aws.amazon.com/AmazonRDS/latest/AuroraUserGuide/rds-proxy-network-prereqs.html&lt;/a&gt;&lt;/p&gt;

</description>
    </item>
    <item>
      <title>Monitoring user login through Cloudtrail for IAM Identity Center[AWS]</title>
      <dc:creator>Md. Mizanur Rahman</dc:creator>
      <pubDate>Thu, 07 Sep 2023 15:29:56 +0000</pubDate>
      <link>https://dev.to/mizaniftee/monitoring-user-login-through-cloudtrail-for-iam-identity-centeraws-4g5j</link>
      <guid>https://dev.to/mizaniftee/monitoring-user-login-through-cloudtrail-for-iam-identity-centeraws-4g5j</guid>
      <description>&lt;p&gt;&lt;strong&gt;AWS IAM Identity Center&lt;/strong&gt; helps you securely create or connect your identities and manage their access centrally across AWS accounts and applications. IAM Identity Center is the recommended approach for workforce authentication and authorization on AWS for organizations of any size and type.&lt;/p&gt;

&lt;p&gt;As there is no &lt;strong&gt;lockout/notification&lt;/strong&gt; system for wrong login attempt in &lt;strong&gt;IAM Identity Center&lt;/strong&gt;, so we will discuss how to configure a system by which we could be notified/get wrong login info.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Config Procedure:&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;ul&gt;
&lt;li&gt;Create a Cloudtrail in that AWS account where the IAM Identity center is configured&lt;/li&gt;
&lt;li&gt;Enable Cloudwatch log + Cloudwatch log group + S3 Storage location&lt;/li&gt;
&lt;li&gt;Create Cloudwatch Logs Metric Filter&lt;/li&gt;
&lt;li&gt;Create SNS and send alarm notifications.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F94szpkypzjuc8t0njkax.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F94szpkypzjuc8t0njkax.png" alt="Image description" width="599" height="142"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Creating Cloudtrail:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Foonl8lvm2msziuakrhg6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Foonl8lvm2msziuakrhg6.png" alt="Image description" width="450" height="444"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Event in Cloudtrail&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Frkfe0cv9mzpbkvywcduj.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Frkfe0cv9mzpbkvywcduj.png" alt="Image description" width="761" height="520"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Create Cloudwatch Metric Filter:&lt;/strong&gt;&lt;br&gt;
Now we have to go to &lt;strong&gt;Cloudwatch group&lt;/strong&gt; and set the metric by which Cloudwatch alert will be generated.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fy7ilq29p7376apc198yo.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fy7ilq29p7376apc198yo.png" alt="Image description" width="800" height="115"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Add below pattern&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fbydjak4gpnvd4wm85f1y.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fbydjak4gpnvd4wm85f1y.png" alt="Image description" width="683" height="233"&gt;&lt;/a&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;{ $.eventSource = "signin.amazonaws.com" &amp;amp;&amp;amp; $.serviceEventDetails.CredentialVerification = "Failure" }
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;After setting the pattern, you could test the pattern at the time of metric creation.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fy14jen5wn9eh1r4qta40.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fy14jen5wn9eh1r4qta40.png" alt="Image description" width="641" height="345"&gt;&lt;/a&gt;&lt;br&gt;
Now we need to put some values for the &lt;strong&gt;metric&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fgdscl04rzh8lu5hpc09r.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fgdscl04rzh8lu5hpc09r.png" alt="Image description" width="511" height="522"&gt;&lt;/a&gt;&lt;br&gt;
Save the changes, so metric will be created and it's time to create a cloudwatch alarm.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F3ycc87l4rvqe0cyqamze.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F3ycc87l4rvqe0cyqamze.png" alt="Image description" width="800" height="68"&gt;&lt;/a&gt;&lt;br&gt;
Now we set like below to set the threshold values for login attempts.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fqfr8wrwry8yifr1g2yfo.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fqfr8wrwry8yifr1g2yfo.png" alt="Image description" width="734" height="278"&gt;&lt;/a&gt;&lt;br&gt;
Set &lt;strong&gt;conditions **per requirements and press "&lt;/strong&gt;next**"&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F76bgi1sh7xvxeegdq0o9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F76bgi1sh7xvxeegdq0o9.png" alt="Image description" width="729" height="345"&gt;&lt;/a&gt;&lt;br&gt;
it's time to set &lt;strong&gt;notification policies&lt;/strong&gt; with &lt;strong&gt;SNS&lt;/strong&gt;. &lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Before that we need create a **SNS **with email endpoint to get the alert to the mail.&lt;/p&gt;
&lt;h1&gt;
  
  
  How to create SNS:
&lt;/h1&gt;

&lt;ul&gt;
&lt;li&gt;Create SNS with email &lt;code&gt;subscription&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;First create a topic with **standard **type. Give a name and description.&lt;/li&gt;
&lt;li&gt;After creating the "topic", go to that topic.&lt;/li&gt;
&lt;li&gt;Create a "&lt;strong&gt;Subscription&lt;/strong&gt;" where protocol "&lt;strong&gt;Email&lt;/strong&gt;" and set the *&lt;em&gt;endpoint *&lt;/em&gt; [email address]to which we want to get the email.&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Foylue0ecxlkxam8cnfht.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Foylue0ecxlkxam8cnfht.png" alt="Image description" width="741" height="407"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;So, we will get alert mail like below if any wrong attempt for login crosses the threshold value.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2ccno1pcyneau72xw3pl.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F2ccno1pcyneau72xw3pl.png" alt="Image description" width="703" height="131"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
    </item>
  </channel>
</rss>
