Note:

You are viewing the documentation for an older major version of the AWS CLI (version 1).

AWS CLI version 2, the latest major version of AWS CLI, is now stable and recommended for general use. To view this page for the AWS CLI version 2, click here. For more information see the AWS CLI version 2 installation instructions and migration guide.

[ aws . redshift-data ]

execute-statement

Description

Runs an SQL statement, which can be data manipulation language (DML) or data definition language (DDL). This statement must be a single SQL statement. Depending on the authorization method, use one of the following combinations of request parameters:

  • Secrets Manager - when connecting to a cluster, provide the secret-arn of a secret stored in Secrets Manager which has username and password . The specified secret contains credentials to connect to the database you specify. When you are connecting to a cluster, you also supply the database name, If you provide a cluster identifier (dbClusterIdentifier ), it must match the cluster identifier stored in the secret. When you are connecting to a serverless workgroup, you also supply the database name.
  • Temporary credentials - when connecting to your data warehouse, choose one of the following options:
    • When connecting to a serverless workgroup, specify the workgroup name and database name. The database user name is derived from the IAM identity. For example, arn:iam::123456789012:user:foo has the database user name IAM:foo . Also, permission to call the redshift-serverless:GetCredentials operation is required.
    • When connecting to a cluster as an IAM identity, specify the cluster identifier and the database name. The database user name is derived from the IAM identity. For example, arn:iam::123456789012:user:foo has the database user name IAM:foo . Also, permission to call the redshift:GetClusterCredentialsWithIAM operation is required.
    • When connecting to a cluster as a database user, specify the cluster identifier, the database name, and the database user name. Also, permission to call the redshift:GetClusterCredentials operation is required.

For more information about the Amazon Redshift Data API and CLI usage examples, see Using the Amazon Redshift Data API in the Amazon Redshift Management Guide .

See also: AWS API Documentation

Synopsis

  execute-statement
[--client-token <value>]
[--cluster-identifier <value>]
--database <value>
[--db-user <value>]
[--parameters <value>]
[--secret-arn <value>]
--sql <value>
[--statement-name <value>]
[--with-event | --no-with-event]
[--workgroup-name <value>]
[--cli-input-json <value>]
[--generate-cli-skeleton <value>]
[--debug]
[--endpoint-url <value>]
[--no-verify-ssl]
[--no-paginate]
[--output <value>]
[--query <value>]
[--profile <value>]
[--region <value>]
[--version <value>]
[--color <value>]
[--no-sign-request]
[--ca-bundle <value>]
[--cli-read-timeout <value>]
[--cli-connect-timeout <value>]

Options

--client-token (string)

A unique, case-sensitive identifier that you provide to ensure the idempotency of the request.

--cluster-identifier (string)

The cluster identifier. This parameter is required when connecting to a cluster and authenticating using either Secrets Manager or temporary credentials.

--database (string)

The name of the database. This parameter is required when authenticating using either Secrets Manager or temporary credentials.

--db-user (string)

The database user name. This parameter is required when connecting to a cluster as a database user and authenticating using temporary credentials.

--parameters (list)

The parameters for the SQL statement.

(structure)

A parameter used in a SQL statement.

name -> (string)

The name of the parameter.

value -> (string)

The value of the parameter. Amazon Redshift implicitly converts to the proper data type. For more information, see Data types in the Amazon Redshift Database Developer Guide .

Shorthand Syntax:

name=string,value=string ...

JSON Syntax:

[
  {
    "name": "string",
    "value": "string"
  }
  ...
]

--secret-arn (string)

The name or ARN of the secret that enables access to the database. This parameter is required when authenticating using Secrets Manager.

--sql (string)

The SQL statement text to run.

--statement-name (string)

The name of the SQL statement. You can name the SQL statement when you create it to identify the query.

--with-event | --no-with-event (boolean)

A value that indicates whether to send an event to the Amazon EventBridge event bus after the SQL statement runs.

--workgroup-name (string)

The serverless workgroup name or Amazon Resource Name (ARN). This parameter is required when connecting to a serverless workgroup and authenticating using either Secrets Manager or temporary credentials.

--cli-input-json (string) Performs service operation based on the JSON string provided. The JSON string follows the format provided by --generate-cli-skeleton. If other arguments are provided on the command line, the CLI values will override the JSON-provided values. It is not possible to pass arbitrary binary values using a JSON-provided value as the string will be taken literally.

--generate-cli-skeleton (string) Prints a JSON skeleton to standard output without sending an API request. If provided with no value or the value input, prints a sample input JSON that can be used as an argument for --cli-input-json. If provided with the value output, it validates the command inputs and returns a sample output JSON for that command.

Global Options

--debug (boolean)

Turn on debug logging.

--endpoint-url (string)

Override command's default URL with the given URL.

--no-verify-ssl (boolean)

By default, the AWS CLI uses SSL when communicating with AWS services. For each SSL connection, the AWS CLI will verify SSL certificates. This option overrides the default behavior of verifying SSL certificates.

--no-paginate (boolean)

Disable automatic pagination.

--output (string)

The formatting style for command output.

  • json
  • text
  • table

--query (string)

A JMESPath query to use in filtering the response data.

--profile (string)

Use a specific profile from your credential file.

--region (string)

The region to use. Overrides config/env settings.

--version (string)

Display the version of this tool.

--color (string)

Turn on/off color output.

  • on
  • off
  • auto

--no-sign-request (boolean)

Do not sign requests. Credentials will not be loaded if this argument is provided.

--ca-bundle (string)

The CA certificate bundle to use when verifying SSL certificates. Overrides config/env settings.

--cli-read-timeout (int)

The maximum socket read time in seconds. If the value is set to 0, the socket read will be blocking and not timeout. The default value is 60 seconds.

--cli-connect-timeout (int)

The maximum socket connect time in seconds. If the value is set to 0, the socket connect will be blocking and not timeout. The default value is 60 seconds.

Output

ClusterIdentifier -> (string)

The cluster identifier. This element is not returned when connecting to a serverless workgroup.

CreatedAt -> (timestamp)

The date and time (UTC) the statement was created.

Database -> (string)

The name of the database.

DbUser -> (string)

The database user name.

Id -> (string)

The identifier of the SQL statement whose results are to be fetched. This value is a universally unique identifier (UUID) generated by Amazon Redshift Data API.

SecretArn -> (string)

The name or ARN of the secret that enables access to the database.

WorkgroupName -> (string)

The serverless workgroup name or Amazon Resource Name (ARN). This element is not returned when connecting to a provisioned cluster.