Skip to main content

Prerequisites

If the cluster is configured within a VPC, then Cube must have a network route to the cluster.

Setup

Manual

Add the following to a .env file in your Cube project:

Password Authentication

IAM Authentication

For enhanced security, you can configure Cube to use IAM authentication instead of username and password. When running in AWS (EC2, ECS, EKS with IRSA), the driver can use the instance’s IAM role to obtain temporary database credentials automatically. Omit CUBEJS_DB_USER and CUBEJS_DB_PASS to enable IAM authentication:
The driver uses the AWS SDK’s default credential chain (IAM instance profile, EKS IRSA, etc.) to obtain temporary database credentials via the redshift:GetClusterCredentialsWithIAM API.

IAM Role Assumption

For cross-account access or enhanced security, you can configure Cube to assume an IAM role:

Cube Cloud

In some cases you’ll need to allow connections from your Cube Cloud deployment IP address to your database. You can copy the IP address from either the Database Setup step in deployment creation, or from Settings → Configuration in your deployment.
The following fields are required when creating an AWS Redshift connection:
Cube Cloud AWS Redshift Configuration Screen

OIDC workload identity

Instead of a database password, Cube Cloud deployments can authenticate to Redshift with OIDC workload identity: an IAM role in your account trusts Cube’s OIDC issuer, and the driver uses it to obtain temporary database credentials via IAM authentication. Set AWS_ROLE_ARN alongside the IAM authentication variables and omit CUBEJS_DB_USER / CUBEJS_DB_PASS:
See the AWS OIDC guide for the IAM role, trust policy, and permissions setup. Cube Cloud also supports connecting to data sources within private VPCs if single-tenant infrastructure is used. Check out the VPC connectivity guide for details.

Environment Variables

1 Required when using password-based authentication. When using IAM authentication, omit these and set CUBEJS_DB_REDSHIFT_CLUSTER_IDENTIFIER and CUBEJS_DB_REDSHIFT_AWS_REGION instead. The driver uses the AWS SDK’s default credential chain (IAM instance profile, EKS IRSA, or OIDC workload identity in Cube Cloud) to obtain temporary database credentials.

Pre-Aggregation Feature Support

count_distinct_approx

Measures of type count_distinct_approx can not be used in pre-aggregations when using AWS Redshift as a source database.

Pre-Aggregation Build Strategies

To learn more about pre-aggregation build strategies, head here.
By default, AWS Redshift uses batching to build pre-aggregations.

Batching

Cube requires the Redshift user to have ownership of a schema in Redshift to support pre-aggregations. By default, the schema name is prod_pre_aggregations. It can be set using the pre_aggregations_schema configration option. No extra configuration is required to configure batching for AWS Redshift.

Export bucket

AWS Redshift only supports using AWS S3 for export buckets.

AWS S3

For improved pre-aggregation performance with large datasets, enable export bucket functionality by configuring Cube with the following environment variables:
Ensure the AWS credentials are correctly configured in IAM to allow reads and writes to the export bucket in S3.

SSL

To enable SSL-encrypted connections between Cube and AWS Redshift, set the CUBEJS_DB_SSL environment variable to true. For more information on how to configure custom certificates, please check out Enable SSL Connections to the Database.