Skip to main content

AWS IAM credentials

Install Respire.Aws and configure an AWS SDK AWSCredentials provider. The package uses AWS SDK for .NET's SigV4 signer to create 15 minute tokens; Respire renews live connections before token expiry through IRespireCredentialProvider.

dotnet add package Respire.Aws
using Amazon;
using Amazon.Runtime;
using Respire;
using Respire.Aws;

var awsCredentials = FallbackCredentialsFactory.GetCredentials();

var elasticache = new RespireOptions
{
Endpoints = { new RespireEndpoint("cache.example.amazonaws.com", 6379) },
UseTls = true,
CredentialProvider = new ElastiCacheIamCredentialProvider(
awsCredentials, RegionEndpoint.USEast1, "my-cache", "my-user", isServerless: true),
};

var memoryDb = new RespireOptions
{
Endpoints = { new RespireEndpoint("cluster.example.amazonaws.com", 6379) },
UseTls = true,
CredentialProvider = new MemoryDbIamCredentialProvider(
awsCredentials, RegionEndpoint.USEast1, "my-cluster", "my-user"),
};

For ElastiCache, pass the serverless cache name or provisioned replication group ID. Serverless caches add the ResourceType=ServerlessCache signing parameter; provisioned deployments omit it. ElastiCache requires lowercase cache names and the IAM-enabled user's user ID to match its username. ElastiCache IAM auth supports Redis OSS 7.0+ and Valkey 7.2+; MemoryDB supports Redis OSS or Valkey 7.0+. MemoryDB uses the cluster name and IAM-enabled username.

Both services require IAM permission to connect to the selected resource and user. ElastiCache IAM authentication also requires TLS. Keep TLS enabled for both services. IAM tokens expire after 15 minutes; the default CredentialRefreshBeforeExpiry is five minutes. Do not set it to 15 minutes or more. AWS terminates IAM-authenticated connections after 12 hours unless the client reauthenticates with a fresh token.

Use Protocol = RespProtocol.Resp3 when provider-backed connections use Pub/Sub. Respire needs RESP3 to reauthenticate a subscribed connection without dropping its subscriptions. The credential provider receives the cancellation token for AWS credential resolution and signing. Respire does not own or dispose the AWS credentials provider. Keep credentials and signed tokens out of logs.