ACD411

RDS authentication: fast, effortless, cheap — pick two

Room: Tech Stage | Time: 20:00

Every RDS connection must prove who it is, and each authentication method makes you to choose two out of three: fast, effortless, or cheap. IAM-based authentication looks like the enlightened pick: no secret to rotate, nothing extra to pay for. Then p99 latency hits the ceiling while the database sits idle. This is the unfiltered story of chasing multi-second latencies through Aurora Serverless, a test lab and RDS Proxy (with real graphs) and why RDS IAM auth never lands on “fast” for free.

The talk presents RDS IAM authentication as the obvious upgrade over managed secrets: effortless and cheap. Then, it frames the real question as a “trilemma": fast, effortless, cheap, where the user has to pick two. A hands-on investigation with a bare psql, an instrumented test lab, and IAM-vs-password comparisons across Serverless and provisioned Aurora, and a week-long AWS support escalation, all this proved that IAM auth never lands on “fast” without spending the “cheap” corner on RDS Proxy. It closes with a concrete takeaway: before trusting IAM auth, time your first cold connection yourself.

Yevhenii "Yev" Dytyniuk
Cloud Consultant/Engineer