Rasa Studio v1.13.x → v1.14.x
What’s New
Studio version 1.14 introduces AWS IAM Database Authentication for RDS connections, significantly enhancing your deployment’s security posture.Before You Upgrade
Review the following guide to enable IAM authentication in your environment. The guide covers both database IAM authentication (new in v1.14) and S3 storage setup (for those migrating from persistent volumes).Overview
This version allows you to replace static database passwords with secure, temporary IAM tokens for enhanced security. Note: S3 storage with IAM has always been supported in Studio. This guide focuses on the new IAM database authentication feature. S3 setup steps are applicable only if you’re moving to S3 storage or setting it up for the first time. This guide explains what you need to do to enable IAM database authentication in your environment.⚠️ Important: Model Retraining Required (Only When Moving to S3)
If you are moving from persistent volumes to S3 for model storage, you will need to either copy your existing models to S3 or retrain all your assistants.When This Applies
- ✅ Applies if: You currently use persistent volumes and are moving to S3 storage
- ❌ Does NOT apply if: You already use S3 storage (with or without IAM)
- ❌ Does NOT apply if: You are only enabling IAM database authentication (not changing storage)
Why Retraining is Needed (When Moving to S3)
- Current models stored in persistent volumes will not be accessible after moving to S3
- This is a one-time requirement when you first move to S3 storage
- Your training data and assistant configurations are not affected and remain available
- Alternative: You can copy models from persistent volumes to S3 instead of retraining
What You Need to Do (If Moving to S3)
- Choose Your Approach:
- Option A: Copy existing models from persistent volumes to S3 (recommended to avoid retraining)
- Option B: Retrain all active assistants (if you prefer to regenerate models)
- Plan Ahead: Schedule time for either copying models or retraining all active assistants
- Test Environment: Consider testing in a staging environment first
If You Already Use S3
- No Retraining Required: Your existing S3-stored models will continue to work
- No Impact: Enabling IAM database authentication does not affect your models
🚀 How to Enable IAM Authentication
Step 1: Set Up AWS Infrastructure
Create IAM Roles
You need to create IAM roles that your application can use:-
Create RDS IAM Role:
- Name:
your-app-rds-role - Trust policy: Allow EKS service accounts to assume this role (see example below)
- Attach policy for RDS database connection
- Name:
-
Create S3 IAM Role:
- Name:
your-app-s3-role - Trust policy: Allow EKS service accounts to assume this role (see example below)
- Attach policy for S3 bucket access
- Name:
Required IAM Policies
RDS Policy (attach to your RDS role):- Go to AWS RDS console → Your database instance
- The instance ID is shown in the instance details (e.g.,
mydb-instance-1) - Or use AWS CLI:
aws rds describe-db-instances --query 'DBInstances[*].DBInstanceIdentifier'
Configure EKS Service Accounts
Service accounts are automatically created when you configure Helm chart annotations.-
Create or Verify OIDC Provider: Ensure your EKS cluster has an OIDC provider configured
Check if OIDC provider exists:
- Go to AWS IAM console → Identity providers
- Look for your EKS cluster’s OIDC provider URL
- Go to IAM → Identity providers → Add provider
- Select “OpenID Connect”
- Provider URL:
https://oidc.eks.YOUR-REGION.amazonaws.com/id/YOUR-OIDC-ID - Audience:
sts.amazonaws.com - Click “Add provider”
-
Configure Helm Chart Annotations:
- Add IAM role annotations to your Helm chart values for the following services
- Service accounts will be automatically created with the IAM role ARNs
- Backend service
- Event ingestion service
- Database migration job
- Rasa Model Service
Step 2: Set Up RDS for IAM Authentication
-
Enable IAM Database Authentication on your RDS instance:
- Go to AWS RDS console
- Select your RDS instance
- Click “Modify”
- Enable “IAM database authentication”
- Apply changes (may require restart)
- Create IAM Database User (connect to your RDS instance as admin):
- Grant Database Permissions:
your_original_db_user with your current database user and your_database_name with your actual database name.
Step 3: Set Up S3 Bucket
-
Create S3 Bucket:
- Go to AWS S3 console
- Click “Create bucket”
- Bucket name:
your-app-shared-storage-ENVIRONMENT(must be globally unique) - Region: Choose your preferred region
- Versioning: Enable versioning
- Default encryption: Enable → Choose “AES-256”
- Block public access: Enable all 4 options:
- ✅ Block all public access
- ✅ Block public access to buckets and objects granted through new public bucket or access point policies
- ✅ Block public access to buckets and objects granted through any public bucket or access point policies
- ✅ Block public access to buckets and objects granted through new ACLs and uploading objects with public ACLs
- Click “Create bucket”
-
Configure Bucket Policy:
- In “Permissions” tab, find “Bucket policy”
- Click “Edit” and add this policy (replace YOUR-BUCKET-NAME and YOUR-ACCOUNT-ID):
Step 4: Update Your Application Configuration
Add these configuration values to your Helm chart:Database IAM Configuration
Add to theconfig.database section of your Helm chart values:
- Backend service
- Event ingestion service
- Database migration job
S3 Configuration (for Rasa Pro)
Add to therasa.rasa.overrideEnv section of your Helm chart values:
- Rasa Model Service
Step 5: Deploy and Test
- Deploy your updated application
- Verify database connections are working
- Retrain your assistants (only if you’re moving from persistent volumes to S3)
Rasa Studio v1.12.x → v1.13.x
What’s New
We’ve made important improvements to Rasa Studio’s database migrations:- No more
superuserrequired: In earlier versions, certain database migrations required a user with superuser privileges. This is no longer necessary. All migrations can now be completed using a standard database user.
Before You Upgrade
If you’re upgrading from a version beforev1.13.x, please follow the below steps.
Step-by-Step Upgrade Instructions
-
Upgrade to
v1.12.7First This ensures that all necessary database migrations are applied before moving to the1.13.xversion -
Mark Migrations as Complete
After upgrading to
v1.12.7, run the following SQL command on your Studio database:
v1.13.x or Later
After completing the steps above, you’re ready to upgrade to the latest version of Rasa Studio.