opensearch-project / opensearch-project/data-prepper

Support IAM Auth for DocumentDB Connections

Open
#5,983 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

enhancement follow up
Dominant language
Java
Stars
374
Forks
354
Avg merge
3d 18h
Merged PRs (30d)
8

Description

Is your feature request related to a problem? Please describe.
It would be nice to be able to connect to DocumentDB using IAM credentials instead of username/password. This functionality is supported by DocumentDB and the mongodb driver.

DocumentDB IAM Auth Docs

Describe the solution you'd like
Make the authentication option in documentdb-pipeline optional. When not provided, the connection will use the IAM credentials of the underlying process.

Describe alternatives you've considered (Optional)
Currently works using username / password, but this approach is less secure. IAM credentials are generally a more secure option.

Additional context
None.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at the documentdb-pipeline authentication option and the MongoDB driver connection setup, using the linked DocumentDB IAM Auth documentation as context. Verify that omitting authentication uses the underlying process's IAM credentials while preserving the existing username/password path, then run the relevant connection tests if available.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, java, mongodb
Domain
backend, database, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.