Amazon Redshift now supports AWS IAM Identity Center authentication with enhanced VPC routing
Amazon Redshift supports IAM Identity Center authentication and enhanced VPC routing, enabling single sign-on with corporate credentials and VPC-based traffic paths for all operations
Amazon Redshift now supports AWS IAM Identity Center authentication for provisioned clusters and serverless workgroups configured with enhanced VPC routing (EVR). This allows single sign-on using corporate credentials, with all traffic traversing Amazon VPC and remaining on the AWS network. With Redshift EVR, traffic between Redshift and other AWS services goes through the VPC, where it can be governed with security groups, network ACLs, and observed in VPC Flow Logs. Authentication and authorization also use AWS PrivateLink interface VPC endpoints within the VPC, following the same network path as other Redshift traffic. The feature also supports IAM Identity Center multi-Region replication for customers running Redshift in a different Region than their primary Identity Center instance.
Why it matters
This change benefits customers with data residency, regulatory, or network-isolation requirements that mandate no public internet egress for analytics, allowing Redshift to be used in environments that avoid public internet access