> ## Documentation Index
> Fetch the complete documentation index at: https://opensre.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS RDS

> Investigate AWS RDS instance health and recent events during incidents

## Overview

OpenSRE uses AWS RDS to investigate database instance health and surface recent operational events — failovers, maintenance windows, parameter changes, and backup activity — when you ask about a managed RDS database.

All RDS API calls are read-only and routed through the shared `aws_sdk_client` allowlist, so the integration cannot mutate your RDS resources.

## Prerequisites

* AWS credentials configured per the [AWS integration](/docs/integrations/cloud/aws) (role ARN recommended)
* An RDS DB instance you want OpenSRE to investigate
* IAM permissions for the two RDS describe actions listed below

## Setup

### Option 1: Interactive CLI

```bash theme={null}
opensre integrations setup rds
```

### Option 2: Environment variables

```bash theme={null}
RDS_DB_INSTANCE_IDENTIFIER=prod-orders-db
AWS_REGION=us-east-1
```

| Variable                     | Default     | Description                                                         |
| ---------------------------- | ----------- | ------------------------------------------------------------------- |
| `RDS_DB_INSTANCE_IDENTIFIER` | —           | **Required.** The DB instance identifier OpenSRE should investigate |
| `AWS_REGION`                 | `us-east-1` | AWS region the instance lives in                                    |
| `RDS_REGION`                 | `us-east-1` | Fallback used only when `AWS_REGION` is not set                     |

Region resolution order (highest priority first):

1. `region` field on the source dict (when configured via the integrations store)
2. `AWS_REGION` environment variable
3. `RDS_REGION` environment variable
4. `us-east-1` (default)

## Credentials

The integration only needs two read-only RDS actions on the same IAM role or user used for the [AWS integration](/docs/integrations/cloud/aws):

```json theme={null}
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "rds:DescribeDBInstances",
        "rds:DescribeEvents"
      ],
      "Resource": "*"
    }
  ]
}
```

If you already use the AWS managed `ReadOnlyAccess` policy, both actions are covered.

## Tools

| Tool                    | AWS API call              | What it returns                                                                                                                     |
| ----------------------- | ------------------------- | ----------------------------------------------------------------------------------------------------------------------------------- |
| `describe_rds_instance` | `rds:DescribeDBInstances` | Status, engine + version, instance class, Multi-AZ, endpoint, storage, AZ, backup window                                            |
| `describe_rds_events`   | `rds:DescribeEvents`      | Recent events (failovers, maintenance, parameter changes, backups). Defaults to last 60 minutes; bounded to 20160 minutes (14 days) |

Both tools become available whenever `rds.db_instance_identifier` is present in the resolved sources.

### Use cases

* Verifying RDS instance status (`available`, `modifying`, `failed`)
* Detecting Multi-AZ failover events around an incident timestamp
* Tracing recent maintenance, parameter group changes, or backup activity that may correlate with the incident

## Verify

There is no dedicated `opensre integrations verify rds` target today. Confirm AWS credentials work (see [AWS](/docs/integrations/cloud/aws)), then start `opensre` and ask, e.g. *"What's the status of prod-orders-db? Any recent failovers?"*

## Troubleshooting

| Symptom                                       | Fix                                                                                      |
| --------------------------------------------- | ---------------------------------------------------------------------------------------- |
| **AccessDenied on `rds:DescribeDBInstances`** | Add the IAM policy above to the role or user used by the AWS integration                 |
| **DBInstanceNotFound**                        | Confirm `RDS_DB_INSTANCE_IDENTIFIER` matches an instance in `AWS_REGION`                 |
| **Tool reports the wrong region**             | Check the region resolution order above for a stale store `region` or wrong `AWS_REGION` |

## Security

* Use read-only IAM (`Describe*` only).
* Prefer role ARN / least privilege over long-lived keys.
* Store identifiers and credentials out of source control.
