[GH-ISSUE #2610] SAML Federated user to PSQL/MySQL with IAM Authentication and segregated permissions #879

Closed
opened 2026-03-07 20:56:06 +03:00 by kerem · 0 comments
Owner

Originally created by @Gunslito on GitHub (May 14, 2024).
Original GitHub issue: https://github.com/dbeaver/cloudbeaver/issues/2610

Hello,

I would like to ask you a question. I've been looking at documentation on how to set this up, but in the federation, SSO, and IAM Authentication part, I couldn't find the exact process.

I'm using Cloudbeaver AWS Edition, and I'm specifically connecting to a PostgreSQL database.

In the database, I'm using IAM Authentication, and I want to use AWS SAML federation to connect the federated user with the database user of the same name, and prevent them from connecting with a user of a different name.

For example:

gunslito@example.com is federated through AWS IAM Identity Center to Cloudbeaver, connecting to the db-psql-1 as the user gunslito@example.com. The role/permission set/etc. should not allow the user gunslito@example.com to connect with a different user.

How can I achieve this?

An IAM/role/user policy or permission set would be very helpful on the documentation.

Originally created by @Gunslito on GitHub (May 14, 2024). Original GitHub issue: https://github.com/dbeaver/cloudbeaver/issues/2610 Hello, I would like to ask you a question. I've been looking at documentation on how to set this up, but in the federation, SSO, and IAM Authentication part, I couldn't find the exact process. I'm using Cloudbeaver AWS Edition, and I'm specifically connecting to a PostgreSQL database. In the database, I'm using IAM Authentication, and I want to use AWS SAML federation to connect the federated user with the database user of the same name, and prevent them from connecting with a user of a different name. For example: gunslito@example.com is federated through AWS IAM Identity Center to Cloudbeaver, connecting to the db-psql-1 as the user gunslito@example.com. The role/permission set/etc. should not allow the user gunslito@example.com to connect with a different user. How can I achieve this? An IAM/role/user policy or permission set would be very helpful on the documentation.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/cloudbeaver#879
No description provided.