Beta Web identity authentication is gated by a feature flag. Contact Lightdash support to enable it for your organization. What Beta means.
sts:AssumeRoleWithWebIdentity. Lightdash stores no AWS secrets, and you can revoke access at any time by editing or deleting the role.
The role’s trust policy pins two values that Lightdash shows in the connection form:
- Subject: your Lightdash instance’s identity. It is the same for every connection on the instance.
- Audience: a value Lightdash generates for your connection and ties to your organization. No other organization can use it, so a role that requires it can only be used by your connection.
Before you start
You need:- Permission to create IAM roles and policies in the AWS account that runs Athena.
- The Athena settings for the connection: region, catalog, database, and the S3 staging directory for query results. See Athena connection settings.
Connect Athena
1
Choose web identity in Lightdash
In your project’s connection settings, choose Athena as the warehouse type, then choose Web Identity (No Keys) as the Authentication Type.Lightdash generates an Audience and shows the Subject. Select Show trust policy to see the trust policy filled in with both values, and copy it.
2
Create the IAM role
In the AWS IAM console, create a role with a Custom trust policy and paste the trust policy from Lightdash. It has this shape:
3
Give the role access to Athena
Attach a permissions policy that lets the role run queries, read the Glue catalog and your data, and write query results. Replace the bucket names, region, and account ID with your own:If your tables are encrypted with a customer-managed KMS key, also allow
kms:Decrypt on that key. Narrow the Glue resources to your catalog, databases, and tables if your security policy requires it.4
Finish the connection
Back in Lightdash, paste the role’s ARN into IAM Role ARN, fill in the rest of the Athena settings, and save.Lightdash tests the connection before saving. The test also checks that the role refuses an audience Lightdash never issued. If the role accepts one, the trust policy doesn’t require your audience and the test fails until you add the
accounts.google.com:oaud condition.Create the role with Terraform
Copy the subject and audience from the connection form:aws_iam_role.lightdash_athena.