Cybersecurity/AWS Cybersecurity papers/AWS Secrets Example
From Cramsession
Jump to navigationJump to search
✍️ Verified Author: Mflavell • Click to view professional profile & credentials
AWS Secrets Manager Retrieval on EC2 via IAM Instance Profiles
Overview
Storing secrets outside of source code and configuration files is a conerstone of cybersecurity. Fortunatley AWS includeds "AWS Secrets Manger" intended for this purpose.
Some of the KEY features of AWS Secrets manager are:
- Granular access controls
- Auduable access (Know who, what and when)
- Secret history
- Seemless intergration with AWS services
- Regional replication
This paper provides a demonstration of securing secrets with AWS Serets manager.
Step 1: Create the secret
- From AWS console open secerts manager.
- Select Other type of secret
- Use the "Key / Value" Option
- Provice and key and a value
- Click next
- Provice a name for the secret
- Click next
- Turn on (or off) automatic rotation
- Click next
- Click store
Great! Now we have a secret!. However nothing will work without IAM permissions!
Step 2: Configure IAM Permissions and Instance Profile
- Open EC2, Select Instances
- Open your sandbox EC2 instance
- Select Actions > Security > Modift IAM Role
- Select "Create IAM Role"
- Let's call the role "Secret_read"
- Select "Use Existing Policy"
- Select "AWSSecretsManagerClientReadOnlyAccess"
- Select "Create Role"
Step 3: Setup the sandbox
1. Verify IMDSv2 Credential Acquisition
lets do this on Amazon Linux - Much easier!
Install python:
sudo dnf update -y sudo dnf install -y python3 python3-pip python3 --version pip3 --version
Create the v-env:
mkdir ~/secrets-lab && cd ~/secrets-lab python3 -m venv venv source venv/bin/activate pip install --upgrade pip pip install boto3
Step 4: Create the code
Create the test code, fetch.py
import json
import boto3
client = boto3.client("secretsmanager", region_name="us-east-1")
payload = {
"username": "db_admin",
"password": "SuperSecretPassword123!",
"host": "mydb.internal",
}
response = client.create_secret(
Name="app/database_creds",
Description="Application DB Credentials",
SecretString=json.dumps(payload),
)
print(f"Created secret ARN: {response['ARN']}")
Step 5: Run the code
python3 fetch.py
{'Test': 'This is secret'}
Step 5: Lab Teardown & Cost Management
AWS Secrets Manager incurs $0.40/secret/month (prorated hourly). To prevent ongoing charges after completing lab tests, force-delete the secret without entering the default recovery retention period: