AWS Secrets Manager

· 1 min read · AWS

AWS Secrets Manager is a managed service to store and retrieve secrets such as database passwords, API keys and tokens, so they do not have to be written in the code, in configuration files or in the Terraform state.

Key concepts #

  • Secret: a value (text or JSON) with a name, encrypted with a KMS key. It keeps versions, identified by the labels AWSCURRENT and AWSPREVIOUS.
  • Automatic rotation: a Lambda function changes the password periodically in the secret and in the database. Rotation is built in for RDS, Aurora, Redshift and DocumentDB.
  • Access control with IAM policies and, optionally, resource policies, including cross-account access. Every read is logged in CloudTrail.
  • Managed master passwords: RDS can create and rotate the admin password of a database in Secrets Manager without anyone seeing it.
  • Replication of secrets to other Regions.
  • Secrets Manager or Parameter Store? Systems Manager Parameter Store is cheaper for configuration values and simple secrets. Secrets Manager adds rotation, replication and cross-account sharing.

Pricing #

A charge per secret per month plus a charge per 10,000 API calls. See the Secrets Manager pricing.

With Terraform #

The resources are aws_secretsmanager_secret, aws_secretsmanager_secret_version and aws_secretsmanager_secret_rotation. The data sources aws_secretsmanager_secret_version read a value. Be aware that values read or written by Terraform end up in the state file: use manage_master_user_password = true in aws_db_instance, which keeps the password out of the state, and protect and encrypt the state.

See tutorials:

More tutorials that use Secrets Manager

#AWS #Security #AWS KMS