All skills
aws avatar

/connecting-to-data-source

@b33847d

Create and troubleshoot AWS Glue connections to JDBC databases (Oracle, SQL Server, PostgreSQL, MySQL, RDS), Redshift, Snowflake, and BigQuery. Gathers connection hints from user, discovers existing connections and RDS/Redshift candidates, registers credentials in Secrets Manager or IAM DB auth, configures VPC, and tests. Triggers on: connect to database, set up Glue connection, register data source, connect to Snowflake/BigQuery/RDS, connection timeout, test connection, troubleshoot connection. Do NOT use for moving data (use ingesting-into-data-lake), creating tables (use creating-data-lake-table), queries (use querying-data-lake), catalog exploration (use exploring-data-catalog), or SaaS (Salesforce, ServiceNow, SAP, MongoDB, Kafka).

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/connecting-to-data-source

This session only. Nothing lands on disk.

referencesjdbc-setup.md

≈893 tokens on demand. Your agent reads this file only when SKILL.md points to it.

JDBC Connection Setup

AWS Glue JDBC connections for Oracle, SQL Server, PostgreSQL, MySQL, MariaDB, Amazon RDS, Amazon Aurora, and Amazon Redshift.

Contents

URL Formats and Drivers

Engine JDBC URL template Driver class
Oracle jdbc:oracle:thin:@//<host>:<port>/<service> oracle.jdbc.OracleDriver
SQL Server jdbc:sqlserver://<host>:<port>;databaseName=<db> com.microsoft.sqlserver.jdbc.SQLServerDriver
PostgreSQL jdbc:postgresql://<host>:<port>/<db> org.postgresql.Driver
MySQL / MariaDB jdbc:mysql://<host>:<port>/<db> com.mysql.cj.jdbc.Driver
Redshift jdbc:redshift://<cluster>.<region>.redshift.amazonaws.com:5439/<db> com.amazon.redshift.jdbc.Driver

For Oracle, prefer the service name form (@//host:port/service). SID form (@host:port:SID) works but is deprecated in Oracle 12c+.

Built-in Drivers

Glue includes drivers for Oracle, SQL Server, PostgreSQL, MySQL, and Redshift. No JDBC_DRIVER_JAR_URI needed.

Custom Driver Upload

For driver versions not built into Glue, upload the JAR to S3 and reference:

aws s3 cp ojdbc8-21.jar s3://<scripts-bucket>/jdbc-drivers/

Add to connection properties:

"JDBC_DRIVER_JAR_URI": "s3://<scripts-bucket>/jdbc-drivers/ojdbc8-21.jar",
"JDBC_DRIVER_CLASS_NAME": "oracle.jdbc.OracleDriver"

Connection JSON Template

{
  "Name": "<connection-name>",
  "ConnectionType": "JDBC",
  "ConnectionProperties": {
    "JDBC_CONNECTION_URL": "<url>",
    "SECRET_ID": "<secrets-manager-arn-or-name>",
    "JDBC_ENFORCE_SSL": "true"
  },
  "PhysicalConnectionRequirements": {
    "SubnetId": "subnet-xxxxx",
    "SecurityGroupIdList": ["sg-xxxxx"],
    "AvailabilityZone": "<region>-<az>"
  }
}

The secret should contain username and password keys. Omit USERNAME/PASSWORD from properties when using SECRET_ID.

Redshift

Redshift accepts both JDBC password auth and IAM-based GetClusterCredentials.

Password-based: use the JDBC template above.

IAM-based (preferred for human/role users): search AWS docs for "Redshift GetClusterCredentials Glue". The Glue role needs redshift:GetClusterCredentials on the cluster; no Secrets Manager secret.

For Redshift Serverless, use the workgroup endpoint and redshift-serverless:GetCredentials.

RDS and Aurora Considerations

  • RDS endpoint format: <instance-id>.<hash>.<region>.rds.amazonaws.com
  • Aurora cluster endpoint (writer): <cluster-id>.cluster-<hash>.<region>.rds.amazonaws.com
  • Aurora reader endpoint (read-only, load balanced): <cluster-id>.cluster-ro-<hash>.<region>.rds.amazonaws.com -- prefer for ETL reads
  • Aurora custom endpoints: target a subset of instances, useful for dedicated ETL reader pools

IAM database authentication (Aurora MySQL, Aurora PostgreSQL, RDS MySQL, RDS PostgreSQL):

  • Enable on the DB cluster/instance: --enable-iam-database-authentication
  • Create a DB user CREATE USER etl_user IDENTIFIED WITH AWSAuthenticationPlugin AS 'RDS'
  • No Secrets Manager secret needed; the Glue role calls rds-db:connect at runtime to get a 15-minute token
  • See credential-security.md for the full IAM policy

Prefer IAM auth over password auth where supported.

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill includes some security considerations such as dynamic script generation for troubleshooting and a surface for indirect prompt injection. While these warrant review, they are used within the skill's intended functionality to register and test data source connections. See detailed analysis for context.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at b33847d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
Other metadata
metadata
{
  "version": "1",
  "argument-hint": "'[source-type|connection-name|hostname]'"
}

README badge

README badge for aws/agent-toolkit-for-aws/connecting-to-data-source