MemoryDB
MemoryDB
Opens an SSM port-forward to an Amazon MemoryDB (Valkey / Redis OSS) cluster through the bastion host and authenticates with a short-lived IAM auth token instead of a MemoryDB user password.
MemoryDB is a redis service with memorydb: true. The token uses the same
presigned-URL scheme as ElastiCache IAM auth. The only difference is that it is
signed for the memorydb service rather than elasticache, and a token signed
for the wrong service is simply rejected. den re-mints it every 13 minutes (tokens
live 15).
Configuration
services:
- name: "EU DEV MemoryDB" # type stays redis — naming it keeps MemoryDB findable with /
type: redis
env: eu-dev
redis:
memorydb: true
local_port: 50181
reconnect: true
redis_host: orders-dev-0001-001.orders-dev.abc123.memorydb.eu-central-1.amazonaws.com
cache_name: orders-dev # the MemoryDB cluster name
user_id: iam-user-01 # MemoryDB user with authentication mode "iam"| Field | Required | Description |
|---|---|---|
memorydb | yes | true selects MemoryDB token signing. Cannot be combined with serverless |
redis_host | yes | Endpoint to forward to. Use the shard’s primary node endpoint, see Limitations |
cache_name | yes | Cluster name. It is the host the token is signed for |
user_id | yes | MemoryDB user name (IAM authentication mode) |
local_port | no | Local end of the tunnel (default 16379) |
reconnect | no | Auto-reopen the SSM port-forward when it drops (e.g. SSM idle timeout). The token is renewed while connected either way |
Without cache_name and user_id den still opens the tunnel but mints no token.
The env: reference supplies the bastion, aws_profile (opens the SSM session),
credential_profile (the identity the token is signed as) and aws_region_code.
Prerequisites
- AWS CLI v2 and the Session Manager plugin; a valid SSO session.
- Valkey or Redis OSS 7.0+ on the cluster. IAM auth does not exist below that.
- A MemoryDB user in IAM mode, attached to the cluster’s ACL:
aws memorydb create-user --user-name iam-user-01 \ --authentication-mode Type=iam --access-string "on ~* +@all" aws memorydb update-acl --acl-name <acl> --user-names-to-add iam-user-01 - IAM:
memorydb:Connecton both the cluster and the user ARN (arn:aws:memorydb:<region>:<account>:cluster/<name>and…:user/iam-user-01). redis-cliwith TLS support. MemoryDB always requires TLS.
Usage
- Launch
den, open Connect, select the MemoryDB service and pressc. - Press
yto copy the command. It includes the current token:redis-cli -h localhost -p 50181 --tls --user iam-user-01 -a "<token>" pcopies only the token, andrre-mints it now.- Or skip the copying: in the detail view,
trunsredis-cliin a terminal tab next to the logs, already logged in. The token reaches it throughREDISCLI_AUTH, not the command line. ddisconnects. It also stops the clients in the service’s terminal tabs.
Limitations
- Single-shard clusters only. MemoryDB always runs in cluster mode. With
several shards, keys on other shards answer with
MOVED <private-ip>:6379, an address that only exists inside the VPC. Don’t useredis-cli -c; its redirects cannot follow through the tunnel. - Point
redis_hostat the primary node. The cluster endpoint (clustercfg.…) can resolve to a replica, which answers writes withMOVED. Find the primary withaws memorydb describe-clusters --cluster-name <name> --show-shard-details. After a failover the primary moves andredis_hostneeds updating. - Connections last at most 12 hours. MemoryDB disconnects IAM-authenticated
connections after 12h. Reconnect with a fresh token (
yagain).
Last updated on