• Reference
  • Version · 6.0
  • Change Automation Reference

Liquibase parameters for AWS

Last updated: September 29, 2026

These parameters control how Liquibase authenticates to AWS services and to Amazon RDS and Aurora databases. They require Liquibase Secure with the Liquibase AWS extension.

Note: The reference-scoped parameters on this page are not accepted as command-line flags. Set them in your liquibase.properties file, as environment variables, or as Java system properties with -D.

Available parameters

Name

Type

Description

liquibase.aws.authType LIQUIBASE_AWS_AUTH_TYPE

String

Selects the authentication mechanism for AWS database connections. Set to IAM to use IAM database authentication on Amazon RDS and Aurora. The value is case-insensitive. This parameter is required for IAM authentication, and an aws-rds-iam password reference is required alongside it. Setting it without that reference causes Liquibase to fail before connecting rather than use a static password.

liquibase.aws.region LIQUIBASE_AWS_REGION

String

AWS region used to generate the IAM database token. You can also supply the region inline in the password value as aws-rds-iam,your_region, which takes precedence over this parameter. Liquibase fails if no region resolves from either source.

liquibase.aws.roleArn LIQUIBASE_AWS_ROLE_ARN

String

IAM role ARN that Liquibase assumes through AWS STS before generating the database token. Use it for cross-account access, or when the rds-db:connect permission is attached to a role rather than to your own identity. You can also supply it inline as the third element of the password value.

liquibase.aws.sessionName LIQUIBASE_AWS_SESSION_NAME

String

Session name applied when assuming a role through AWS STS. Default: liquibase-rds-iam.

liquibase.aws.reference.authType LIQUIBASE_AWS_REFERENCE_AUTH_TYPE

String

Selects the authentication mechanism for the reference connection of diff and diff-changelog. Leave it unset to inherit liquibase.aws.authType. Set it to DEFAULT to authenticate the reference connection with a password while the target connection uses IAM. The value is case-insensitive.

liquibase.aws.reference.region LIQUIBASE_AWS_REFERENCE_REGION

String

AWS region used to generate the IAM database token for the reference connection. Leave it unset to inherit liquibase.aws.region. Setting it runs a cross-region diff without embedding the region in the reference password value.

liquibase.aws.reference.roleArn LIQUIBASE_AWS_REFERENCE_ROLE_ARN

String

IAM role ARN that Liquibase assumes for the reference connection. Leave it unset to inherit liquibase.aws.roleArn. Setting it runs a cross-role diff without embedding the role in the reference password value. This parameter has no opt-out value, so a reference connection cannot decline an inherited role ARN. Give the reference connection its own role ARN instead.

liquibase.aws.reference.sessionName LIQUIBASE_AWS_REFERENCE_SESSION_NAME

String

Session name applied when the reference connection assumes a role through AWS STS. Leave it unset to inherit liquibase.aws.sessionName. It has no effect unless the reference connection assumes a role.