-
Notifications
You must be signed in to change notification settings - Fork 79
/
Copy pathAWSSecretsManagerRedshiftDriver.java
139 lines (123 loc) · 4.55 KB
/
AWSSecretsManagerRedshiftDriver.java
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
/*
* Copyright 2018 Amazon.com, Inc. or its affiliates. All Rights Reserved.
*
* Licensed under the Apache License, Version 2.0 (the "License"). You may not use this file except in compliance with
* the License. A copy of the License is located at
*
* http://aws.amazon.com/apache2.0
*
* or in the "license" file accompanying this file. This file is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR
* CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions
* and limitations under the License.
*/
package com.amazonaws.secretsmanager.sql;
import java.sql.SQLException;
import com.amazonaws.secretsmanager.caching.SecretCache;
import com.amazonaws.secretsmanager.caching.SecretCacheConfiguration;
import com.amazonaws.services.secretsmanager.AWSSecretsManager;
import com.amazonaws.services.secretsmanager.AWSSecretsManagerClientBuilder;
import com.amazonaws.util.StringUtils;
/**
* <p>
* Provides support for accessing Redshift databases using credentials stored
* within AWS Secrets Manager.
* </p>
*
* <p>
* Configuration properties are specified using the "redshift" subprefix (e.g
* drivers.redshift.realDriverClass).
* </p>
*/
public final class AWSSecretsManagerRedshiftDriver extends AWSSecretsManagerDriver {
/**
* The Redshift error code for when a user logs in using an invalid password.
*
* See <a href=
* "https://www.postgresql.org/docs/9.6/static/errcodes-appendix.html">Postgres documentation</a> (Redshift is built on Postgres).
*/
public static final String ACCESS_DENIED_FOR_USER_USING_PASSWORD_TO_DATABASE = "28P01";
public static final String SUBPREFIX = "redshift";
/**
* Default driver class to use.
*/
public static final String DEFAULT_DRIVER = "com.amazon.redshift.Driver";
static {
AWSSecretsManagerDriver.register(new AWSSecretsManagerRedshiftDriver());
}
/**
* Constructs the driver setting the properties from the properties file using
* system properties as defaults.
* Instantiates the secret cache with default options.
*/
public AWSSecretsManagerRedshiftDriver() {
super();
}
/**
* Constructs the driver setting the properties from the properties file using
* system properties as defaults.
* Uses the passed in SecretCache.
*
* @param cache Secret cache to use to retrieve secrets
*/
public AWSSecretsManagerRedshiftDriver(SecretCache cache) {
super(cache);
}
/**
* Constructs the driver setting the properties from the properties file using
* system properties as defaults.
* Instantiates the secret cache with the passed in client builder.
*
* @param builder Builder used to instantiate cache
*/
public AWSSecretsManagerRedshiftDriver(AWSSecretsManagerClientBuilder builder) {
super(builder);
}
/**
* Constructs the driver setting the properties from the properties file using
* system properties as defaults.
* Instantiates the secret cache with the provided AWS Secrets Manager client.
*
* @param client AWS Secrets Manager client to instantiate cache
*/
public AWSSecretsManagerRedshiftDriver(AWSSecretsManager client) {
super(client);
}
/**
* Constructs the driver setting the properties from the properties file using
* system properties as defaults.
* Instantiates the secret cache with the provided cache configuration.
*
* @param cacheConfig Cache configuration to instantiate cache
*/
public AWSSecretsManagerRedshiftDriver(SecretCacheConfiguration cacheConfig) {
super(cacheConfig);
}
@Override
public String getPropertySubprefix() {
return SUBPREFIX;
}
@Override
public boolean isExceptionDueToAuthenticationError(Exception e) {
if (e instanceof SQLException) {
SQLException sqle = (SQLException) e;
String sqlState = sqle.getSQLState();
return sqlState.equals(ACCESS_DENIED_FOR_USER_USING_PASSWORD_TO_DATABASE);
}
return false;
}
@Override
public String constructUrlFromEndpointPortDatabase(String endpoint, String port, String dbname) {
String url = "jdbc:redshift://" + endpoint;
if (!StringUtils.isNullOrEmpty(port)) {
url += ":" + port;
}
if (!StringUtils.isNullOrEmpty(dbname)) {
url += "/" + dbname;
}
return url;
}
@Override
public String getDefaultDriverClass() {
return DEFAULT_DRIVER;
}
}