Cybersecurity/AWS Cybersecurity papers/AWS Secrets Example: Difference between revisions
From Cramsession
Jump to navigationJump to search
✍️ Verified Author: Mflavell • Click to view professional profile & credentials
| (4 intermediate revisions by the same user not shown) | |||
| Line 2: | Line 2: | ||
=== Overview === | === Overview === | ||
Storing secrets outside of source code and configuration files is a conerstone of cybersecurity. Fortunatley AWS includeds "AWS Secrets Manger" intended for this purpose. | |||
Some of the KEY features of AWS Secrets manager are: | |||
* Granular access controls | |||
* Auduable access (Know who, what and when) | |||
* Secret history | |||
* Seemless intergration with AWS services | |||
* Regional replication | |||
This paper provides a demonstration of securing secrets with AWS Serets manager. | |||
=== Step 1: Create the secret === | |||
# From AWS console open secerts manager. | |||
# Select '''Other type of secret''' | |||
# Use the "Key / Value" Option | |||
# Provice and key and a value | |||
# Click next | |||
# Provice a name for the secret | |||
# Click next | |||
# Turn on (or off) automatic rotation | |||
# Click next | |||
# Click store | |||
Great! Now we have a secret!. However nothing will work without IAM permissions! | |||
=== Step 2: Configure IAM Permissions and Instance Profile === | === Step 2: Configure IAM Permissions and Instance Profile === | ||
# Open EC2, Select Instances | |||
# Open your sandbox EC2 instance | |||
# Select Actions > Security > Modift IAM Role | |||
# Select "Create IAM Role" | |||
# Let's call the role "Secret_read" | |||
# Select "Use Existing Policy" | |||
# Select "AWSSecretsManagerClientReadOnlyAccess" | |||
# Select "Create Role"<br /> | |||
=== Step 3: Setup the sandbox === | |||
=== Step 3: | |||
==== 1. Verify IMDSv2 Credential Acquisition ==== | ==== 1. Verify IMDSv2 Credential Acquisition ==== | ||
lets do this on Amazon Linux - Much easier! | |||
'''Install python:''' | |||
sudo dnf update -y | |||
sudo dnf install -y python3 python3-pip | |||
python3 --version | |||
pip3 --version | |||
'''<br />Create the v-env:''' | |||
mkdir ~/secrets-lab && cd ~/secrets-lab | |||
python3 -m venv venv | |||
source venv/bin/activate | |||
pip install --upgrade pip | |||
pip install boto3 | |||
==== Step 4: Create the code ==== | |||
Create the test code, fetch.py | |||
import json | |||
import boto3 | |||
client = boto3.client("secretsmanager", region_name="us-east-1") | |||
payload = { | |||
"username": "db_admin", | |||
"password": "SuperSecretPassword123!", | |||
"host": "mydb.internal", | |||
} | |||
response = client.create_secret( | |||
Name="app/database_creds", | |||
Description="Application DB Credentials", | |||
SecretString=json.dumps(payload), | |||
) | |||
print(f"Created secret ARN: {response['ARN']}") | |||
=== Step 5: | ==== Step 5: Run the code ==== | ||
python3 fetch.py | |||
{'Test': 'This is secret'} | |||
==== Step 5: Lab Teardown & Cost Management ==== | |||
AWS Secrets Manager incurs $0.40/secret/month (prorated hourly). To prevent ongoing charges after completing lab tests, force-delete the secret without entering the default recovery retention period: | AWS Secrets Manager incurs $0.40/secret/month (prorated hourly). To prevent ongoing charges after completing lab tests, force-delete the secret without entering the default recovery retention period: | ||
Latest revision as of 21:35, 6 October 2026
AWS Secrets Manager Retrieval on EC2 via IAM Instance Profiles
Overview
Storing secrets outside of source code and configuration files is a conerstone of cybersecurity. Fortunatley AWS includeds "AWS Secrets Manger" intended for this purpose.
Some of the KEY features of AWS Secrets manager are:
- Granular access controls
- Auduable access (Know who, what and when)
- Secret history
- Seemless intergration with AWS services
- Regional replication
This paper provides a demonstration of securing secrets with AWS Serets manager.
Step 1: Create the secret
- From AWS console open secerts manager.
- Select Other type of secret
- Use the "Key / Value" Option
- Provice and key and a value
- Click next
- Provice a name for the secret
- Click next
- Turn on (or off) automatic rotation
- Click next
- Click store
Great! Now we have a secret!. However nothing will work without IAM permissions!
Step 2: Configure IAM Permissions and Instance Profile
- Open EC2, Select Instances
- Open your sandbox EC2 instance
- Select Actions > Security > Modift IAM Role
- Select "Create IAM Role"
- Let's call the role "Secret_read"
- Select "Use Existing Policy"
- Select "AWSSecretsManagerClientReadOnlyAccess"
- Select "Create Role"
Step 3: Setup the sandbox
1. Verify IMDSv2 Credential Acquisition
lets do this on Amazon Linux - Much easier!
Install python:
sudo dnf update -y sudo dnf install -y python3 python3-pip python3 --version pip3 --version
Create the v-env:
mkdir ~/secrets-lab && cd ~/secrets-lab python3 -m venv venv source venv/bin/activate pip install --upgrade pip pip install boto3
Step 4: Create the code
Create the test code, fetch.py
import json
import boto3
client = boto3.client("secretsmanager", region_name="us-east-1")
payload = {
"username": "db_admin",
"password": "SuperSecretPassword123!",
"host": "mydb.internal",
}
response = client.create_secret(
Name="app/database_creds",
Description="Application DB Credentials",
SecretString=json.dumps(payload),
)
print(f"Created secret ARN: {response['ARN']}")
Step 5: Run the code
python3 fetch.py
{'Test': 'This is secret'}
Step 5: Lab Teardown & Cost Management
AWS Secrets Manager incurs $0.40/secret/month (prorated hourly). To prevent ongoing charges after completing lab tests, force-delete the secret without entering the default recovery retention period: