We are currently trying to set up Athena access between two accounts. The goal is that the EC2 instance role from one account assumes a specific role from a different AWS account that grants access to its Athena.
Using Instance Profile authentication in the driver does not work because we couldn't find a way to configure the preferred role.
If IAM Profile is used instead, the Athena ODBC driver throws an error:
FAILED!
Simba DriverIAMSupport (8600) Connection Error: No AWS Profile found:
The error message is misleading because the driver definitely finds the profile. Querying Athena using this profile via CLI works fine. Connecting Athena with source_profile attribute or using aws_access_key_id and aws_secret_access_key also works.
This is how the profile config looks like:
[profile athena]
role_arn = arn:aws:iam:123456789:role/athena-read-role
credential_source = Ec2InstanceMetadata
region = eu-central-1
Tested with:
- Athena ODBC driver version: 1.1.6 (32 & 64 bit)
- Windows Server 2012 & Windows Server 2016
References: