import { type RedshiftClientConfig } from '@aws-sdk/client-redshift'; import { CreateRedshiftCredentials } from '@lightdash/common'; export declare const isExpiredAwsTokenError: (error: unknown) => boolean; export type RedshiftIamDbCredentials = { dbUser: string; dbPassword: string; expiration: Date | undefined; }; type AwsCredentialsConfig = RedshiftClientConfig['credentials']; /** * Build the AWS identity used to call the Redshift credential APIs. * Precedence: explicit session credentials → assume-role layered over static * keys (or the default chain) → static keys → ambient default chain. * * Returning `undefined` lets the AWS SDK fall back to its default credential * chain (instance role / IRSA / env) — only meaningful for self-hosted * deployments whose host has an attached AWS role. */ export declare const getRedshiftAwsCredentials: (credentials: CreateRedshiftCredentials) => AwsCredentialsConfig; /** * Mint a short-lived Redshift database user + password from AWS IAM, for either * a provisioned cluster (GetClusterCredentials) or a serverless workgroup * (GetCredentials). The returned credentials are used with the normal pg * driver to connect. */ export declare const mintRedshiftIamCredentials: (credentials: CreateRedshiftCredentials) => Promise; export {}; //# sourceMappingURL=redshiftIamCredentials.d.ts.map