Control: RDS DB instances should have iam authentication enabled
Description
Checks if an AWS Relational Database Service (AWS RDS) instance has AWS Identity and Access Management (IAM) authentication enabled.
Usage
Run the control in your terminal:
powerpipe control run aws_compliance.control.rds_db_instance_iam_authentication_enabled
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run aws_compliance.control.rds_db_instance_iam_authentication_enabled --share
SQL
This control uses a named query:
select arn as resource, case when iam_database_authentication_enabled then 'ok' else 'alarm' end as status, case when iam_database_authentication_enabled then title || ' IAM authentication enabled.' else title || ' IAM authentication not enabled.' end as reason , region, account_idfrom aws_rds_db_instance;