[Enhancement]: Passwordless AWS IAM authentication for Amazon DocumentDB (and RDS Postgres in the RAG API) #16413
sadypro
started this conversation in
Feature Requests & Suggestions
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
What
Let LibreChat connect to Amazon DocumentDB 5.0 using the workload's AWS IAM identity (IRSA or EKS Pod Identity on EKS, or an instance profile) instead of a database password stored in
MONGO_URI. A companion change would give the RAG API the same thing for RDS/Aurora PostgreSQL (pgvector).Why
Teams running LibreChat on EKS currently have to put a DocumentDB password in
MONGO_URIand a Postgres password inPOSTGRES_PASSWORD, then store and rotate those secrets. IAM authentication removes the stored secret and uses short-lived credentials that refresh automatically. DocumentDB 5.0 is already the supported target (seepackages/data-schemas/misc/documentdb/documentdb-compat.md), but LibreChat has no IAM auth path today.Proposed implementation (LibreChat)
MONGO_AUTH_MECHANISM=aws-iam, plus an optionalMONGO_AWS_ROLE_ARNto assume an extra role. When unset, behavior is unchanged.librechat.yamlbecauseconnectDb()runs before app config loads, like every otherMONGO_*setting.packages/api/src/db/auth.ts:resolveMongoAuth({ uri, mechanism, roleArn, credentialProvider? })returns{ authMechanism: 'MONGODB-AWS', authSource: '$external', authMechanismProperties: { AWS_CREDENTIAL_PROVIDER } }.fromNodeProviderChain()(orfromTemporaryCredentialswhen a role ARN is set) from@aws-sdk/credential-providers, which is already a dependency. The installedmongodb^6.14 driver supportsAWS_CREDENTIAL_PROVIDER.api/db/connect.js: wiring only. It merges the options in and logs a sanitized copy (never credentials).config/scripts inherit the change throughconnectDb.authSourceother than$externaleach throw. When AWS credentials can't be resolved, a clear hint is logged.resolveMongoAuthusing a substitute provider, and a wiring test forconnect.js. There's also a live test in the existingmisc/documentdbharness that is skipped unlessDOCUMENTDB_IAM_URIis set, becauseMONGODB-AWScan't run againstmongodb-memory-server..env.exampleentries, and an "IAM authentication" section indocumentdb-compat.mdcovering the$externaluser, TLS bundle andretryWrites=false.Companion change (RAG API, separate repo)
POSTGRES_AUTH_MECHANISM=aws-iamwould generate an RDS IAM token (boto3 generate_db_auth_token) for each new connection on both of rag_api's connection paths: the SQLAlchemy/psycopg2 engine and the asyncpg pool. TLS is required. The only LibreChat change for this would be.env.exampledocumentation. I'm happy to open that proposal in the rag_api repo if you'd like it tracked there.Compatibility
I'd like to implement this myself and can open the PR against
devonce it's approved.All reactions