AWS::QuickSight::DataSource RedshiftIAMParameters
A structure that grants Amazon QuickSight access to your cluster and make a call to the redshift:GetClusterCredentials
API. For more information on the redshift:GetClusterCredentials
API, see GetClusterCredentials
.
Syntax
To declare this entity in your AWS CloudFormation template, use the following syntax:
JSON
{ "AutoCreateDatabaseUser" :
Boolean
, "DatabaseGroups" :[ String, ... ]
, "DatabaseUser" :String
, "RoleArn" :String
}
YAML
AutoCreateDatabaseUser:
Boolean
DatabaseGroups:- String
DatabaseUser:String
RoleArn:String
Properties
AutoCreateDatabaseUser
-
Automatically creates a database user. If your database doesn't have a
DatabaseUser
, set this parameter toTrue
. If there is noDatabaseUser
, Amazon QuickSight can't connect to your cluster. TheRoleArn
that you use for this operation must grant access toredshift:CreateClusterUser
to successfully create the user.Required: No
Type: Boolean
Update requires: No interruption
DatabaseGroups
-
A list of groups whose permissions will be granted to Amazon QuickSight to access the cluster. These permissions are combined with the permissions granted to Amazon QuickSight by the
DatabaseUser
. If you choose to include this parameter, theRoleArn
must grant access toredshift:JoinGroup
.Required: No
Type: Array of String
Minimum:
1 | 1
Maximum:
64 | 50
Update requires: No interruption
DatabaseUser
-
The user whose permissions and group memberships will be used by Amazon QuickSight to access the cluster. If this user already exists in your database, Amazon QuickSight is granted the same permissions that the user has. If the user doesn't exist, set the value of
AutoCreateDatabaseUser
toTrue
to create a new user with PUBLIC permissions.Required: No
Type: String
Minimum:
1
Maximum:
64
Update requires: No interruption
RoleArn
-
Use the
RoleArn
structure to allow Amazon QuickSight to callredshift:GetClusterCredentials
on your cluster. The calling principal must haveiam:PassRole
access to pass the role to Amazon QuickSight. The role's trust policy must allow the Amazon QuickSight service principal to assume the role.Required: Yes
Type: String
Minimum:
20
Maximum:
2048
Update requires: No interruption