> ## Documentation Index
> Fetch the complete documentation index at: https://docs.formal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Redshift

> How to connect to an Amazon Redshift Resource using the Formal Connector

<Note>
  Redshift Resources require Connector version 2.4.0 or later.
</Note>

## Overview

Amazon Redshift speaks the Postgres wire protocol. The Connector proxies Redshift with its Postgres engine and parses SQL with the Redshift dialect. Policies, masking, and logs work as they do for [Postgres](/docs/guides/core-concepts/resources/postgres).

## Create a Redshift Resource

<Tabs>
  <Tab title="Control Plane">
    Go to [Resources](https://app.formal.ai/resources) and click **Create Resource**. Set **Technology** to **Redshift**. Set **Hostname** to the cluster endpoint, such as `analytics.abc123xyz789.us-east-1.redshift.amazonaws.com`. The **Port** defaults to `5439`.
  </Tab>

  <Tab title="Terraform">
    ```hcl theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
    resource "formal_resource" "analytics" {
      name       = "analytics-redshift"
      technology = "redshift"
      hostname   = "analytics.abc123xyz789.us-east-1.redshift.amazonaws.com"
      port       = 5439
    }
    ```
  </Tab>
</Tabs>

To create Redshift Resources from your AWS account automatically, turn on Redshift autodiscovery in your [AWS Cloud Account](/docs/guides/integrations/clouds/aws).

## Requirements

### Networking

You may assign any listener port except 8080 (the Connector's health check port). Make sure the Connector can reach the cluster on its port, and that your security groups allow that traffic.

### Database Health Check

Formal periodically connects and runs `SELECT 1`. If you don't configure a database for health checks, Formal uses `dev`. See [Configure Health Check Database](/docs/guides/core-concepts/resources/introduction#configure-health-check-database).

### Native Users

Redshift Resources require a [Native User](/docs/guides/core-concepts/resources/native-users). These credential types are supported:

| Credential type | How the Connector signs in |
| - | - |
| **Password** | Sends the username and password |
| **AWS IAM** | Requests temporary credentials with the Connector's AWS identity |
| **AWS IAM Role** | Assumes the role, then requests temporary credentials |

Grant the Native User the permissions that end users need upstream, and permission to connect to the health check database.

## Authenticate with AWS IAM

With an AWS IAM Native User, the Connector calls `redshift:GetClusterCredentials` for the Native User's username. It then signs in as `IAM:<username>` with the temporary password.

Requirements:

* The Resource hostname must be the provisioned cluster endpoint, in the form `<cluster-id>.<id>.<region>.redshift.amazonaws.com`. Formal reads the cluster ID and region from it.
* The database user must already exist. Formal doesn't create it.
* The Connector's AWS identity, or the role it assumes, needs `redshift:GetClusterCredentials` on the database user:

```json theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "redshift:GetClusterCredentials",
      "Resource": "arn:aws:redshift:us-east-1:123456789012:dbuser:analytics/formal_reader"
    }
  ]
}
```

<Warning>
  AWS IAM Native Users don't work with Redshift Serverless endpoints. Use a
  Password Native User for Redshift Serverless.
</Warning>

## Connect to Redshift

Use `psql` or any Postgres-compatible client:

```bash theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
psql -h CONNECTOR_HOSTNAME -p PORT -d DATABASE_NAME -U FORMAL_USERNAME
```

Replace `CONNECTOR_HOSTNAME`, `PORT`, `DATABASE_NAME`, and `FORMAL_USERNAME` with the right values. You can find your Formal credentials in the [Control Plane](https://app.formal.ai).

**Verify:**

```sql theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
SELECT current_user;
```

The result is the Native User's database user.

### Smart Routing

Several Redshift Resources can share one listener port. Add the Resource name after the database name, as for [Postgres](/docs/guides/core-concepts/resources/postgres#smart-routing):

```bash theme={"languages":{"custom":["/languages/cel.json","/languages/rego.json"]}}
psql -h CONNECTOR_HOSTNAME -p 5439 -d dev@analytics-redshift -U FORMAL_USERNAME
```

## Policy Evaluation

Formal evaluates policies at the **session**, **request**, and **response** stages. Redshift queries populate `input.sql_query` like other SQL Resources. See [Evaluation](/docs/guides/policies/evaluation#sql-resources).

## Next Steps

<CardGroup cols={2}>
  <Card title="Native Users" icon="key" href="/docs/guides/core-concepts/resources/native-users">
    Configure upstream credentials
  </Card>

  <Card title="Policies" icon="shield-check" href="/docs/guides/policies/introduction">
    Write policies for SQL Resources
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.