Skip to main content
Direct clients connect to the Resource gateway on TCP 3306. Use the Resource access name as the client username and enter a short-lived Forge token as the password.
With automatic routing, keep the destination hostname and ordinary client command.

Policy fields and actions

Forge can match database, destination user, command, tables, and a literal-free query pattern. Ordinary and prepared commands and bounded multi-statement admission are supported. Connections and commands can be allowed, flagged, approved, or blocked. Forge can redact exact result columns or remove matching rows. Filtering runs before redaction and preserves framing and NULL. Text-protocol values support the shared redaction strategies and scalar comparisons. Binary results can always be nullified; other strategies require a supported textual column.

Destination authentication

The gateway can use an assigned username and password or generate a temporary AWS IAM database password from its workload identity for RDS and Aurora. Destination TLS and hostname verification are always required.

Current limits

Local infile, compression, change-user, replication, MySQL X Protocol, and arbitrary binary value rewriting are not supported. Missing, duplicate, malformed, or incompatible targeted columns fail closed before the original targeted value is released. See Credentials and identity and Resource Policies.