Pair your devices with a code and playback position follows you: pause on this device, hit resume on the other. Position is saved to the site every minute and on pause.
Open this panel on your other device and enter the same code.
Verified 2026-08-16 against the pages cited in the lessons.
NAME → ROUTE → AUTH → QUERY. Each stage masks the ones below it.
| Stage | Data source enum | Ingestion enum (Q2.3) | First move |
|---|---|---|---|
| Name | UNKNOWN_HOST |
UNRESOLVABLE_HOST |
DNS, DnsResolvers, Region |
| Route | TIMEOUT |
UNROUTABLE_HOST |
3 SG rules, AvailabilityStatus |
| Auth | ACCESS_DENIED |
PERMISSION_DENIED, … |
which role exists, secret, KMS |
| Query | GENERIC_SQL_FAILURE |
SQL_* family |
run the SQL directly |
Full data source enum (8): ACCESS_DENIED | COPY_SOURCE_NOT_FOUND | TIMEOUT | ENGINE_VERSION_NOT_SUPPORTED | UNKNOWN_HOST | GENERIC_SQL_FAILURE | CONFLICT | UNKNOWN
Two error surfaces: create/test failed → DescribeDataSource.ErrorInfo.
Refresh failed → ListIngestions → ErrorInfo (45 values — the better enum).
POST /accounts/{AwsAccountId}/data-sources
required: DataSourceId (unique per account+Region) · Name (1–128) · Type
Type: 38 values. OpenSearch = AMAZON_ELASTICSEARCH (documented!); AMAZON_OPENSEARCH also
exists. Aurora MySQL = AURORA; AURORA_POSTGRESQL separate. No Glue type — go via Athena.CREATION_IN_PROGRESS, not success. Poll describe-data-source.Permissions ≤ 64 · FolderArns ≤ 1 · Tags ≤ 200.LimitExceededException = 409 not 429 — don't blind-retry.| Shape | Verdict |
|---|---|
CredentialPair |
password stored in data source — rotation pain |
CopySourceArn |
borrows from another data source — breaks as COPY_SOURCE_NOT_FOUND |
SecretArn |
✅ Secrets Manager; JSON needs username + password keys |
kms:Decrypt.GetSecretValue against the caller's IAM, not the service role.update-data-source.| Role | Job |
|---|---|
aws-quicksight-s3-consumers-role-v0 |
Athena/S3/Athena Federation — used if it exists |
aws-quicksight-service-role-v0 |
the fallback when consumers role is absent |
aws-quicksight-secretsmanager-role-v0 |
reads granted secrets at view time |
⚠️ Fixes applied to the fallback role do nothing while the consumers role exists.
Athena also needs the workgroup results bucket, not just the data bucket.
KMS-encrypted data: aws kms create-grant --key-id <key> --grantee-principal <role> --operations Decrypt
⚠️ Bucket checkboxes are account-global — unchecking one breaks other teams.
Hand-edited managed policy → screen locks; documented fix is delete the policy.
A VPC connection = ENIs (the "QNI") in your subnets. Not for Athena/S3.
POST /accounts/{AwsAccountId}/vpc-connections
SubnetIds: min 2, max 15 · SecurityGroupIds: 1–16 · RoleArn required
DnsResolvers: ≤15 IPv4 addresses (7–15 chars — no IPv6)
CreationStatus (built?) vs AvailabilityStatus (usable?):
AVAILABLE | UNAVAILABLE | PARTIALLY_AVAILABLE ← the "works sometimes" value.| SG | Direction | Rule |
|---|---|---|
| QNI SG | in | All TCP 0–65535, source = DB's SG |
| QNI SG | out | TCP 5439, dest = DB's SG |
| DB SG | in | TCP 5439, source = QNI's SG |
QNI SG is NOT stateful → return packets arrive on random ports → all-ports inbound is correct. Narrow the source, never the ports. Never all-ports outbound. ⚠️ Docs date these rules to connections created before 2023-04-27 and don't state what applies after — verify empirically or get Support to answer in writing.
| Quota | Value |
|---|---|
| Visual direct-query timeout | 120 s — ⚠️ Redshift driver ignores it → zombie queries |
| Dataset preview timeout | 45 s |
| Columns per file / result set (fields per dataset) | 2,000 |
| Column name / field length | 127 / 2,047 chars (65,534 new prep) |
| Files per S3 manifest | 1,000 |
| SPICE per dataset | 25M rows / 25 GB (Std) · 2B rows / 2 TB (Ent) |
.json; Redshift format: any extension, mandatory honored.URIPrefixes recurse.format only. UTF-8 without BOM. S3 zip/gzip import as-is.Account ID · Region · data source ID + ARN · enum value verbatim · RequestId ·
timestamps · VPC connection ID + AvailabilityStatus · which service role exists.