AWS Training
Modules Listen Certification

← Data Sources and Connectivity

Q1 Cheat sheet — data sources and connectivity

Verified 2026-08-16 against the pages cited in the lessons.

The triage ladder — always in this order

NAME → ROUTE → AUTH → QUERY. Each stage masks the ones below it.

Stage Data source enum Ingestion enum (Q2.3) First move
Name UNKNOWN_HOST UNRESOLVABLE_HOST DNS, DnsResolvers, Region
Route TIMEOUT UNROUTABLE_HOST 3 SG rules, AvailabilityStatus
Auth ACCESS_DENIED PERMISSION_DENIED, … which role exists, secret, KMS
Query GENERIC_SQL_FAILURE SQL_* family run the SQL directly

Full data source enum (8): ACCESS_DENIED | COPY_SOURCE_NOT_FOUND | TIMEOUT | ENGINE_VERSION_NOT_SUPPORTED | UNKNOWN_HOST | GENERIC_SQL_FAILURE | CONFLICT | UNKNOWN

Two error surfaces: create/test failed → DescribeDataSource.ErrorInfo. Refresh failed → ListIngestions → ErrorInfo (45 values — the better enum).

CreateDataSource in one box

POST /accounts/{AwsAccountId}/data-sources
required: DataSourceId (unique per account+Region) · Name (1–128) · Type

Credentials — prefer the secret

Shape Verdict
CredentialPair password stored in data source — rotation pain
CopySourceArn borrows from another data source — breaks as COPY_SOURCE_NOT_FOUND
SecretArn ✅ Secrets Manager; JSON needs username + password keys

The three service roles

Role Job
aws-quicksight-s3-consumers-role-v0 Athena/S3/Athena Federation — used if it exists
aws-quicksight-service-role-v0 the fallback when consumers role is absent
aws-quicksight-secretsmanager-role-v0 reads granted secrets at view time

⚠️ Fixes applied to the fallback role do nothing while the consumers role exists. Athena also needs the workgroup results bucket, not just the data bucket. KMS-encrypted data: aws kms create-grant --key-id <key> --grantee-principal <role> --operations Decrypt ⚠️ Bucket checkboxes are account-global — unchecking one breaks other teams. Hand-edited managed policy → screen locks; documented fix is delete the policy.

VPC connections (Enterprise only)

A VPC connection = ENIs (the "QNI") in your subnets. Not for Athena/S3.

POST /accounts/{AwsAccountId}/vpc-connections
SubnetIds: min 2, max 15 · SecurityGroupIds: 1–16 · RoleArn required
DnsResolvers: ≤15 IPv4 addresses (7–15 chars — no IPv6)

The three SG rules (Redshift example, 5439)

SG Direction Rule
QNI SG in All TCP 0–65535, source = DB's SG
QNI SG out TCP 5439, dest = DB's SG
DB SG in TCP 5439, source = QNI's SG

QNI SG is NOT stateful → return packets arrive on random ports → all-ports inbound is correct. Narrow the source, never the ports. Never all-ports outbound. ⚠️ Docs date these rules to connections created before 2023-04-27 and don't state what applies after — verify empirically or get Support to answer in writing.

Quotas and timeouts (all non-adjustable)

Quota Value
Visual direct-query timeout 120 s — ⚠️ Redshift driver ignores it → zombie queries
Dataset preview timeout 45 s
Columns per file / result set (fields per dataset) 2,000
Column name / field length 127 / 2,047 chars (65,534 new prep)
Files per S3 manifest 1,000
SPICE per dataset 25M rows / 25 GB (Std) · 2B rows / 2 TB (Ent)

S3 manifests

Environment rules

Support case checklist

Account ID · Region · data source ID + ARN · enum value verbatim · RequestId · timestamps · VPC connection ID + AvailabilityStatus · which service role exists.