Skip to main content
Redshift Resources require Connector version 2.4.0 or later.

Overview

Amazon Redshift speaks the Postgres wire protocol. The Connector proxies Redshift with its Postgres engine and parses SQL with the Redshift dialect. Policies, masking, and logs work as they do for Postgres.

Create a Redshift Resource

Go to Resources and click Create Resource. Set Technology to Redshift. Set Hostname to the cluster endpoint, such as analytics.abc123xyz789.us-east-1.redshift.amazonaws.com. The Port defaults to 5439.
To create Redshift Resources from your AWS account automatically, turn on Redshift autodiscovery in your AWS Cloud Account.

Requirements

Networking

You may assign any listener port except 8080 (the Connector’s health check port). Make sure the Connector can reach the cluster on its port, and that your security groups allow that traffic.

Database Health Check

Formal periodically connects and runs SELECT 1. If you don’t configure a database for health checks, Formal uses dev. See Configure Health Check Database.

Native Users

Redshift Resources require a Native User. These credential types are supported: Grant the Native User the permissions that end users need upstream, and permission to connect to the health check database.

Authenticate with AWS IAM

With an AWS IAM Native User, the Connector calls redshift:GetClusterCredentials for the Native User’s username. It then signs in as IAM:<username> with the temporary password. Requirements:
  • The Resource hostname must be the provisioned cluster endpoint, in the form <cluster-id>.<id>.<region>.redshift.amazonaws.com. Formal reads the cluster ID and region from it.
  • The database user must already exist. Formal doesn’t create it.
  • The Connector’s AWS identity, or the role it assumes, needs redshift:GetClusterCredentials on the database user:
AWS IAM Native Users don’t work with Redshift Serverless endpoints. Use a Password Native User for Redshift Serverless.

Connect to Redshift

Use psql or any Postgres-compatible client:
Replace CONNECTOR_HOSTNAME, PORT, DATABASE_NAME, and FORMAL_USERNAME with the right values. You can find your Formal credentials in the Control Plane. Verify:
The result is the Native User’s database user.

Smart Routing

Several Redshift Resources can share one listener port. Add the Resource name after the database name, as for Postgres:

Policy Evaluation

Formal evaluates policies at the session, request, and response stages. Redshift queries populate input.sql_query like other SQL Resources. See Evaluation.

Next Steps

Native Users

Configure upstream credentials

Policies

Write policies for SQL Resources