I have set a new Secrets Manager Credential for connecting to Redshift with rotation enabled, following this tutorial but for Redshift. When I save the secret, although a message stating that the secret is successfully stored and the rotation is enabled, the secret rotation is not working. Credentials must rotate once just afert enabling rotation but I the password never changes. Then, every time a try to force credentials rotation, an error is deplayed saying that "A previous rotation isn't complete".
I have checked the logs in CloudWatch and I can see the following error:
[ERROR] ValueError: Unable to log into database with previous, current, or pending secret of secret arn...
My Redshift cluster is deployed in a private VPC and is not publicly accessible. However, I have verified that:
- The lambda (generated and configured automatically by the SMM) is running in the same VPC as Redshift does and they have the same security group.
- The lambda has the corresponding permissions for secret manager, cloudwatch and EC2 services.
- The VPC has a public NAT Gateway configured. Thus, a private endpoint should not be needed.
- Stored Redshift credentials are correct as I am able to connect from python or DBeaver (ssh tunel) with them.
Am I missing something?