Data

The managed data stores are where the engagement pays off: the database, the warehouse, the lake, and the cache hold what the account exists to protect. Reaching them splits into two moves that recur across every service here. Either the data plane is exposed directly (a publicly reachable endpoint, weak or shared credentials, an over-broad grant), or the control plane hands you the data offline (a shared snapshot, an export to S3, a credential-vending call). Several of these services also run jobs under an attached role, so they double as compute and are cross-referenced into identity where that role is the prize.

What folds in here#

  • RDS: snapshot sharing and restore, and reaching the instance through weak network and auth controls.
  • DynamoDB: Scan, Query, and table export to S3.
  • SageMaker: notebooks, training jobs, and endpoints, and the attached role.
  • Redshift: exposed clusters, temporary credentials, and database grants.
  • Glue: the Data Catalog, job scripts, and running jobs under the Glue role.
  • DocumentDB: exposed Mongo-compatible clusters.
  • ElastiCache: unauthenticated Redis and Memcached.
  • Athena: querying S3 data through the catalog.
  • Lake Formation: governed-table permissions and credential vending.
  • EMR: clusters, steps, and the instance role.
  • Neptune: exposed graph-database clusters.
  • Timestream: querying time-series databases.
  • Keyspaces: Cassandra-compatible tables.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more