【问题标题】:Use an AWS IAM token to connect to a Postgres database using .pgpass使用 AWS IAM 令牌通过 .pgpass 连接到 Postgres 数据库
【发布时间】:2022-09-25 03:49:25
【问题描述】:
在我们公司内部,我们希望基于生成的 IAM 令牌连接到 AWS RDS postgres 数据库。大多数情况下,我们使用 DBeaver 连接到数据库。但是,对于 DBeaver,建立连接需要 .pgpass。
我的问题是如何使用 IAM 令牌实现与 DBeaver 与我们的 AWS RDS 数据库的连接?
提前致谢!
格,
杰伦
标签:
postgresql
amazon-web-services
amazon-rds
amazon-iam
【解决方案1】:
由于未转义 IAM 令牌中的“:”字符,您可能会遇到问题。
我使用下面的 powershell 脚本来更新 AWS Aurora 的 .pgpass 文件,它适用于 DBeaver 22.2。注意$token = $token.Replace(':', '\:'); 行。脚本是基本的,但可以适应其他用例。
param (
[Parameter(Mandatory = $true)][string]$hostname,
[Parameter(Mandatory = $true)][string]$database,
[Parameter(Mandatory = $true)][string]$username,
[Parameter(Mandatory = $false)][int]$port=5432
)
$ErrorActionPreference = "Stop"
$region = $env:AWS_DEFAULT_REGION;
if ($null -eq $region) {
$region = "us-east-1";
}
$token = aws rds generate-db-auth-token --hostname $hostname --port $port --region $region --username $username
if (!$?) { throw "failed to generate iam rds token"}
$token = $token.Replace(':', '\:');
$loc = $env:APPDATA + "\postgresql\pgpass.conf"
if ($null -eq $env:APPDATA) {
$loc = $env:HOME + "/.pgpass";
}
$updated = "$($hostname):$($port):$($database):$($username):$token`n"
if (![IO.File]::Exists($loc)) {
[IO.File]::WriteAllText($loc, $updated);
return;
}
$replaced = "";
foreach ($line in [System.IO.File]::ReadLines($loc))
{
if ($line.ToLower().StartsWith($hostname.ToLower())) {
$replaced += $updated
} else {
$replaced += $line + "`n";
}
}
[IO.File]::WriteAllText($loc, $replaced);