Secrets Manager Redshift credential Rotation fails with "Unable to log into database"

Viewed 369

I have set a new Secrets Manager Credential for connecting to Redshift with rotation enabled, following this tutorial but for Redshift. When I save the secret, although a message stating that the secret is successfully stored and the rotation is enabled, the secret rotation is not working. Credentials must rotate once just afert enabling rotation but I the password never changes. Then, every time a try to force credentials rotation, an error is deplayed saying that "A previous rotation isn't complete".

I have checked the logs in CloudWatch and I can see the following error:

[ERROR] ValueError: Unable to log into database with previous, current, or pending secret of secret arn...

My Redshift cluster is deployed in a private VPC and is not publicly accessible. However, I have verified that:

  1. The lambda (generated and configured automatically by the SMM) is running in the same VPC as Redshift does and they have the same security group.
  2. The lambda has the corresponding permissions for secret manager, cloudwatch and EC2 services.
  3. The VPC has a public NAT Gateway configured. Thus, a private endpoint should not be needed.
  4. Stored Redshift credentials are correct as I am able to connect from python or DBeaver (ssh tunel) with them.

Am I missing something?

0 Answers
Related