What's the best way to share an aurora serverless db cluster across accounts?

Viewed 718

I'm spinning up an aurora serverless db cluster in my org's main account, and am attempting to access it from one of many sub-accounts for the organization, however I'm getting the error message Error: cluster arn:aws:rds:<region>:<mainaccount>:cluster:<clustername> does not belong to the calling account id <subaccount>. Previously I had connectivity working fine, when the cluster was spun up in the sub account, so this appears to be a purely IAM related issue from what I can tell.

So far I've tried:

  • Sharing the cluster with all accounts in the org using the AWS RAM console, which resulted in the same error. Further research revealed that RAM for DB clusters appears to be more for giving cloning access rather than query access.
  • Looking for ways to add policies to the cluster itself that gives the whole organization access to the resource (there doesn't appear to be any way to do this?)

The other thing I'm considering that I haven't tried yet because it feels too heavy (and probably too expensive?) to be the best way to do things:

  • create a role in the main acct giving all org accts access
  • add access to the role in the permissions of my db-access users in the sub account
  • every time I go to make a db call, make an STS call to get temporary credentials to the role in the main account that has DB access
  • use the temporary credentials to access the Data API

That seems more complex than I want it to be though so I thought I'd ask in case anyone knows of a better way--What's the best way to gain access to an aurora serverless cluster using the data api from a non-cluster-owning account in my organization?

Edit: The statement I'm executing to access the DB has this form:

svc.ExecuteStatement(&rdsdataservice.ExecuteStatementInput{
    Schema:aws.String(schema),
    Database:aws.String(db),
    ResourceArn:aws.String(DatabaseARN),
    SecretArn:aws.String(SecretARN),
    Sql: aws.String(`SELECT ... `),
})
0 Answers
Related