Pair your devices with a code and playback position follows you: pause on this device, hit resume on the other. Position is saved to the site every minute and on pause.
Open this panel on your other device and enter the same code.
Starts this lesson and continues through 24 more to the end of the course.
A data source in Quick Sight is not data. It's a small named object holding three things: where
the source is (DataSourceParameters), how to authenticate (Credentials), and how to get there
(VpcConnectionProperties, SslProperties). Datasets — the things SPICE actually fills — are built
on data sources. Get the separation straight and half the permission model of Q3 becomes obvious.
From CreateDataSource (verified 2026-08-16):
POST /accounts/{AwsAccountId}/data-sources HTTP/1.1
Three fields are required: DataSourceId (unique per account per Region), Name (display, 1–128
chars), and Type (the 38-value enum from lesson 1). Everything else is optional — which is how you
get the classic broken state: a data source that exists but can't connect, because nothing forced
you to supply parameters or credentials at creation time.
The optional fields, with their documented constraints:
| Field | Constraint (verbatim from the API page) |
|---|---|
DataSourceParameters |
one member per source type — RedshiftParameters, AthenaParameters, … |
Credentials |
"Currently, only credentials based on user name and password are supported" |
Permissions |
1–64 ResourcePermission objects |
FolderArns |
maximum 1 item |
SslProperties |
{ "DisableSsl": boolean } |
VpcConnectionProperties |
{ "VpcConnectionArn": "…" } — lesson 4 |
Tags |
1–200 items |
Response: Arn, DataSourceId, RequestId, and CreationStatus — one of
CREATION_IN_PROGRESS | CREATION_SUCCESSFUL | CREATION_FAILED | UPDATE_IN_PROGRESS | UPDATE_SUCCESSFUL | UPDATE_FAILED | DELETED.
⚠️ CreateDataSource returning 200 does not mean the connection works. You get
CREATION_IN_PROGRESS back; the connection test happens asynchronously. Poll
DescribeDataSource until the status resolves, and if it's CREATION_FAILED, read
ErrorInfo (lesson 5). Pipelines that fire-and-forget this call discover the failure a day later,
as a refresh error on some downstream dataset.
DataSourceParameters has one member object per source type. Representative shapes, verbatim from
the request syntax (verified 2026-08-16):
"RedshiftParameters": { "ClusterId", "Database", "Host", "Port",
"IAMParameters": { "AutoCreateDatabaseUser", "DatabaseGroups",
"DatabaseUser", "RoleArn" },
"IdentityCenterConfiguration": { "EnableIdentityPropagation" } }
"AthenaParameters": { "WorkGroup", "RoleArn", "ConsumerAccountRoleArn",
"IdentityCenterConfiguration": { "EnableIdentityPropagation" } }
"S3Parameters": { "ManifestFileLocation": { "Bucket", "Key" }, "RoleArn" }
"RdsParameters": { "InstanceId", "Database" }
"MySqlParameters": { "Database", "Host", "Port" }
Read those field names closely — they encode the authorization models of lesson 3:
RdsParameters takes an InstanceId, not a host — Quick Sight can find RDS instances natively.RedshiftParameters accepts ClusterId or Host/Port, plus IAMParameters for connecting
via IAM instead of a database password.AthenaParameters.RoleArn and S3Parameters.RoleArn let a specific data source assume a specific
role, instead of riding the account-wide service role. ConsumerAccountRoleArn exists for
cross-account Athena. (Field names verified on the API page; the full semantics live on the
AthenaParameters and S3Parameters type pages — cite those before you architect around them.)For S3, the ManifestFileLocation points at a JSON manifest. From
Supported formats for Amazon S3 manifest files
(verified 2026-08-16): a Quick Sight-format manifest must have a .json extension; a
Redshift-format manifest (also accepted, with its mandatory flag honored) can have any extension.
All files in one manifest must share format, column count, and column types. URIs lists exact
files; URIPrefixes pulls whole folders recursively. For JSON files, set
globalUploadSettings.format but not delimiter/textqualifier/containsHeader.
The Credentials object offers, per the request syntax: a CredentialPair (username/password,
with optional AlternateDataSourceParameters), a CopySourceArn (borrow credentials from an
existing data source), or a SecretArn.
Prefer the SecretArn. From
Using AWS Secrets Manager secrets instead of database credentials
(verified 2026-08-16):
aws quicksight create-data-source \
--aws-account-id 111122223333 \
--data-source-id sales-mysql \
--name "Sales MySQL" \
--type MYSQL \
--data-source-parameters '{"MySQLParameters":{"Database":"sales","Host":"db.example.internal","Port":3306}}' \
--credentials '{"SecretArn":"arn:aws:secretsmanager:us-east-1:111122223333:secret:sales-db"}' \
--region us-east-1
The rules that matter, all from that page:
username and password keys; both are required, all other keys
are ignored.aws-quicksight-secretsmanager-role-v0.kms:Decrypt. AWS-managed key? No
extra setup.secretsmanager:GetSecretValue is authorized against the API caller's
IAM policy, not the service role. The service role is what's assumed later, when viewers open
dashboards. Two different identities need access, at two different times — this asymmetry is
behind most "works when I create it, fails when they view it" mysteries.⚠️ The UI eats secrets. Verbatim: "Secrets are automatically removed from a data source when
the data source is altered in the UI." Someone edits the host or port in the console, the
SecretArn silently drops off, and the next connection fails auth. The restore is
update-data-source through the API. If your data sources are API-managed, say so in the console
name (sales-mysql [IaC — do not edit in console]) — it's crude and it works.
From the API page (verified 2026-08-16): AccessDeniedException 401,
InvalidParameterValueException 400, CustomerManagedKeyUnavailableException 400,
ResourceExistsException 409, LimitExceededException 409, ConflictException 409,
ResourceNotFoundException 404, ThrottlingException 429, InternalFailureException 500.
Same pattern you learned on CreateIngestion in Q2: LimitExceededException is a 409, not a
429 — don't blind-retry it. And CustomerManagedKeyUnavailableException is this API's tell that
your account's registered CMK is the problem, not your parameters.
create-data-source returned 200. What do you actually know, and what's your next call?CopySourceArn a maintenance hazard compared to SecretArn?sales_manifest.txt in Quick Sight format is rejected. Why?secretsmanager:GetSecretValue — the creator, the service role, or both, and when?CreationStatus: CREATION_IN_PROGRESS. Poll
describe-data-source until it resolves, and read ErrorInfo on failure.SecretArn was removed by the UI edit. Restore it with update-data-source..json extension. (Redshift-format manifests may use
any extension.)aws-quicksight-secretsmanager-role-v0 role is used when viewers load dashboards. Both paths
must work.CreationStatus after creating
a data source. The honest answer is usually nobody, and it frames the lesson.CREATION_FAILED in describe-data-source. Cheap, vivid, reusable in lesson 5.ResourcePermission entries)
with database permissions. Different layer; Q3 and Q5 territory.