Reference

Authentication IAM SigV4


Description

No description available [API reference]

Instructions

IAM SigV4 for Neptune JDBC. SSL is required. Create IAM access keys in the console (same idea as a Stripe secret key), or rely on the default credential chain on an EC2 instance / role.

  1. Sign in to the IAM console.
  2. Create (or reuse) an IAM user or role with Neptune connect/query permissions. Do not use a personal employee login for unattended Linked Server or Power BI refresh.
  3. Open Security credentials and create an access key. Copy Access key ID into User name and Secret access key into Password. Alternatively leave them empty and use an instance profile / AWS_PROFILE.
  4. Set Service region to the cluster region (for example us-east-1). Keep enableSsl=true.
  5. Neptune has no public endpoint. After Finish, replace the host (e.g. MyHostName) (and SSH-tunnel port if you forwarded 8182 locally).
  6. Finish the wizard. Then click Test Connection on the DSN Main UI (the wizard does not run Test Connection).
  7. Done. You can query from C#, Python, PowerShell, and ODBC apps.

Parameters

Parameter Required Default value Options
Name: DriverFilePaths

Label: JDBC driver file(s)

Filled by the wizard after download. Separate multiple JARs with a semicolon (e.g. C:\ZappySys\Jdbc\MyConnector\driver.jar).
YES C:\ZappySys\Jdbc\Amazon Neptune\amazon-neptune-jdbc-driver-3.0.3-all.jar
Name: HostName

Label: Host

JDBC host name or IP (e.g. MyHostName).
YES MyHostName
Name: Port

Label: TCP port

JDBC port (e.g. 8182).
YES 8182
Name: serviceRegion

Label: Service region

AWS region of the Neptune cluster. Required for IAM SigV4 (e.g. us-east-1).
YES us-east-1
Name: DriverClass

Label: Driver class

Optional. Leave blank to auto-detect from the JAR unless SPI is ambiguous (e.g. software.amazon.neptune.jdbc.NeptuneDriver).
software.amazon.neptune.jdbc.NeptuneDriver
Name: EnableSsl

Label: Enable SSL

Enable TLS for this JDBC URL (e.g. Yes from the dropdown).
true
Name Value
Notset
Yes true
No false
Name: UserName

Label: Access key ID

IAM access key ID (not a personal AWS console login). Leave empty to use an instance profile or AWS_PROFILE.
Name: Password

Label: Secret access key

IAM secret access key for the same access key ID. Leave empty for the default credential chain.