Amazon Redshift will no longer support the use of Python UDFs after June 30, 2026.
We will start enforcing it in phases. For more information on the details of Python end of life
and migration options, see the
blog post
Authorizing use of an Amazon KMS customer managed key with Amazon Redshift (Provisioned) and Amazon Redshift Serverless
Amazon Redshift integrates with Amazon Key Management Service (Amazon KMS) to encrypt your data at rest. When you use a customer managed key, you have full control over the key policy, key rotation, and enabling or disabling the key. For more information about customer managed keys, see Customer managed keys in the Amazon Key Management Service Developer Guide.
When Amazon Redshift uses a customer managed key in cryptographic operations, it acts on behalf of the user who is creating or modifying the Amazon Redshift provisioned cluster or Amazon Redshift Serverless resource.
Required permissions
To create and use an Amazon Redshift provisioned cluster or an Amazon Redshift Serverless resource that is encrypted with a customer managed key, a user must have permission to call the following operations on the customer managed key:
kms:CreateGrantkms:GenerateDataKeykms:Encryptkms:Decryptkms:DescribeKey
The owner or administrator of the customer managed key can add these permissions for specific users in the key policy of the customer managed key, or in an IAM policy if the key policy allows it.
Amazon Redshift accesses the customer managed key through Amazon KMS grants. Make sure that your key policy doesn't prevent Amazon Redshift from creating or using grants on the key. For example, explicit Deny statements, or restrictive conditions on Allow statements, can block grant creation and cause operations to fail.
As a security best practice, we recommend that you provide only the permissions that
are required for your use case. For example, you can scope down the
kms:CreateGrant permission by using a condition key such as
kms:GrantIsForAWSResource.
For more information about controlling access to Amazon KMS keys, see Key policies in Amazon KMS and Allowing users in other accounts to use a KMS key in the Amazon Key Management Service Developer Guide.