Cybersecurity/AWS Cybersecurity papers/AWS Secrets Example: Difference between revisions

From Cramsession
Jump to navigationJump to search
✍️ Verified Author: Mflavell • Click to view professional profile & credentials
 
(3 intermediate revisions by the same user not shown)
Line 2: Line 2:


=== Overview ===
=== Overview ===
This guide details the end-to-end setup for creating a secret in AWS Secrets Manager, granting access to an Amazon EC2 instance using an IAM instance profile (eliminating hardcoded credentials), configuring a Python runtime environment on Amazon Linux, and retrieving the secret payload programmatically using boto3.
Storing secrets outside of source code and configuration files is a conerstone of cybersecurity. Fortunatley AWS includeds "AWS Secrets Manger" intended for this purpose.


=== Architecture & Security Model ===


* '''AWS Secrets Manager''': Stores sensitive configuration data encrypted at rest with AWS KMS.
Some of the KEY features of AWS Secrets manager are:
* '''IAM Instance Profile''': Temporary security credentials rotated automatically via the EC2 Instance Metadata Service (IMDSv2). No static AWS access keys are stored on the instance.
* '''Principle of Least Privilege''': The IAM role permissions are restricted strictly to the secretsmanager:GetSecretValue action on the target secret resource ARN.


---
* Granular access controls
* Auduable access (Know who, what and when)
* Secret history
* Seemless intergration with AWS services
* Regional replication


=== Step 1: Create the Secret in AWS Secrets Manager ===


Execute the following command via AWS CLI (or deploy via the AWS Management Console) to generate the secret with a JSON payload:
This paper provides a demonstration of securing secrets with AWS Serets manager.


Note the generated '''ARN''' from the output:
=== Step 1: Create the secret ===


arn:aws:secretsmanager:us-east-1:843771826066:secret:test/secret-cK45Ko
# From AWS console open secerts manager.
# Select '''Other type of secret'''
# Use the "Key / Value" Option
# Provice and key and a value
# Click next
# Provice a name for the secret
# Click next
# Turn on (or off) automatic rotation
# Click next
# Click store




---
Great! Now we have a secret!. However nothing will work without IAM permissions!


=== Step 2: Configure IAM Permissions and Instance Profile ===
=== Step 2: Configure IAM Permissions and Instance Profile ===


==== 1. Create the IAM Role Trust Policy ====
# Open EC2, Select Instances
Save the following trust policy document as ec2-trust-policy.json:
# Open your sandbox EC2 instance
# Select Actions > Security > Modift IAM Role
# Select "Create IAM Role"
# Let's call the role "Secret_read"
# Select "Use Existing Policy"
# Select "AWSSecretsManagerClientReadOnlyAccess"
# Select "Create Role"<br />


Create the role:
=== Step 3: Setup the sandbox ===
 
aws iam create-role
 
--role-name EC2-SecretsManager-ReadOnly
 
--assume-role-policy-document file://ec2-trust-policy.json
 
 
==== 2. Create and Attach the Least-Privilege IAM Policy ====
Save the permissions policy as secrets-policy.json, locking the resource down to the target secret ARN:
 
Attach the policy:
 
aws iam put-role-policy
 
--role-name EC2-SecretsManager-ReadOnly
 
--policy-name SecretsManagerAccessPolicy
 
--policy-document file://secrets-policy.json
 
 
==== 3. Create the Instance Profile and Attach to EC2 ====
 
 
# Create instance profile and add the role
 
aws iam create-instance-profile --instance-profile-name EC2-SecretsManager-Profile
aws iam add-role-to-instance-profile
 
--instance-profile-name EC2-SecretsManager-Profile
 
--role-name EC2-SecretsManager-ReadOnly
 
# Attach to the running EC2 instance
 
aws ec2 associate-iam-instance-profile
 
--instance-id <YOUR_INSTANCE_ID>
 
--iam-instance-profile Name=EC2-SecretsManager-Profile
 
 
''Note: In the AWS Console, this can also be applied via: '''EC2 Console''' -> Select Instance -> '''Actions''' -> '''Security''' -> '''Modify IAM role'''.''
 
---
 
=== Step 3: EC2 System & Python Environment Setup ===
 
Log in to the Amazon Linux instance and configure the runtime.


==== 1. Verify IMDSv2 Credential Acquisition ====
==== 1. Verify IMDSv2 Credential Acquisition ====
Confirm the instance profile is detected:
lets do this on Amazon Linux - Much easier!
 
TOKEN=$(curl -s -S -X PUT "[http://169.254.169.254/latest/api/token](https://www.google.com/search?q=http://169.254.169.254/latest/api/token)" -H "X-aws-ec2-metadata-token-ttl-seconds: 60")
curl -s -H "X-aws-ec2-metadata-token: $TOKEN" [http://169.254.169.254/latest/meta-data/iam/security-credentials/](https://www.google.com/search?q=http://169.254.169.254/latest/meta-data/iam/security-credentials/)
 
The command should return: EC2-SecretsManager-ReadOnly.
 
==== 2. Install Packages & Virtual Environment ====
 
 
# Amazon Linux 2023:
 
sudo dnf update -y
sudo dnf install -y python3 python3-pip
 
# Amazon Linux 2:
 
# sudo yum update -y && sudo yum install -y python3 python3-pip
 
# Set up project workspace
 
mkdir ~/secrets-lab && cd ~/secrets-lab
python3 -m venv venv
source venv/bin/activate
 
# Install AWS SDK
 
pip install --upgrade pip
pip install boto3
 
 
---
 
=== Step 4: Python Retrieval Script ===
 
Create fetch.py.
 
''Note on Python compatibility:'' Including from **future** import annotations ensures the union type syntax (dict | str) parses cleanly across Python 3.7+ through 3.9 environments without throwing TypeError: unsupported operand type(s) for |: 'type' and 'type'.
 
import json
import boto3
from botocore.exceptions import ClientError
 
def get_secret(secret_name: str, region_name: str = "us-east-1") -> dict | str:
"""Retrieve and parse secret from AWS Secrets Manager using IAM instance credentials."""
session = boto3.session.Session()
client = session.client(
service_name="secretsmanager",
region_name=region_name,
)
 
```
try:
    response = client.get_secret_value(SecretId=secret_name)
except ClientError as e:
    raise e
 
if "SecretString" in response:
    secret = response["SecretString"]
    try:
        return json.loads(secret)
    except json.JSONDecodeError:
        return secret
 
return response["SecretBinary"]
 
```
 
if **name** == "**main**":
SECRET_ID = "arn:aws:secretsmanager:us-east-1:843771826066:secret:test/secret-cK45Ko"
REGION = "us-east-1"


```
'''Install python:'''
credentials = get_secret(SECRET_ID, region_name=REGION)
sudo dnf update -y
print("Successfully retrieved credentials payload:")
sudo dnf install -y python3 python3-pip
print(credentials)
python3 --version
pip3 --version


```
'''<br />Create the v-env:'''


==== Execution and Verification ====
mkdir ~/secrets-lab && cd ~/secrets-lab
python3 -m venv venv
source venv/bin/activate
pip install --upgrade pip
pip install boto3


(venv) [ec2-user@ip-10-0-0-5 secrets-lab]$ python fetch.py
Successfully retrieved credentials payload:
{'username': 'db_admin', 'password': 'SampleSecurePassword123!', 'host': 'db.internal'}


==== Step 4: Create the code ====
Create the test code, fetch.py
import json
import boto3
client = boto3.client("secretsmanager", region_name="us-east-1")
payload = {
    "username": "db_admin",
    "password": "SuperSecretPassword123!",
    "host": "mydb.internal",
}
response = client.create_secret(
    Name="app/database_creds",
    Description="Application DB Credentials",
    SecretString=json.dumps(payload),
)
print(f"Created secret ARN: {response['ARN']}")


---


=== Step 5: Lab Teardown & Cost Management ===
==== Step 5: Run the code ====
python3 fetch.py
{'Test': 'This is secret'}


==== Step 5: Lab Teardown & Cost Management ====
AWS Secrets Manager incurs $0.40/secret/month (prorated hourly). To prevent ongoing charges after completing lab tests, force-delete the secret without entering the default recovery retention period:
AWS Secrets Manager incurs $0.40/secret/month (prorated hourly). To prevent ongoing charges after completing lab tests, force-delete the secret without entering the default recovery retention period:

Latest revision as of 21:35, 6 October 2026

AWS Secrets Manager Retrieval on EC2 via IAM Instance Profiles

Overview

Storing secrets outside of source code and configuration files is a conerstone of cybersecurity. Fortunatley AWS includeds "AWS Secrets Manger" intended for this purpose.


Some of the KEY features of AWS Secrets manager are:

  • Granular access controls
  • Auduable access (Know who, what and when)
  • Secret history
  • Seemless intergration with AWS services
  • Regional replication


This paper provides a demonstration of securing secrets with AWS Serets manager.

Step 1: Create the secret

  1. From AWS console open secerts manager.
  2. Select Other type of secret
  3. Use the "Key / Value" Option
  4. Provice and key and a value
  5. Click next
  6. Provice a name for the secret
  7. Click next
  8. Turn on (or off) automatic rotation
  9. Click next
  10. Click store


Great! Now we have a secret!. However nothing will work without IAM permissions!

Step 2: Configure IAM Permissions and Instance Profile

  1. Open EC2, Select Instances
  2. Open your sandbox EC2 instance
  3. Select Actions > Security > Modift IAM Role
  4. Select "Create IAM Role"
  5. Let's call the role "Secret_read"
  6. Select "Use Existing Policy"
  7. Select "AWSSecretsManagerClientReadOnlyAccess"
  8. Select "Create Role"

Step 3: Setup the sandbox

1. Verify IMDSv2 Credential Acquisition

lets do this on Amazon Linux - Much easier!

Install python:

sudo dnf update -y
sudo dnf install -y python3 python3-pip
python3 --version
pip3 --version


Create the v-env:

mkdir ~/secrets-lab && cd ~/secrets-lab
python3 -m venv venv
source venv/bin/activate
pip install --upgrade pip
pip install boto3


Step 4: Create the code

Create the test code, fetch.py

import json
import boto3

client = boto3.client("secretsmanager", region_name="us-east-1")

payload = {
    "username": "db_admin",
    "password": "SuperSecretPassword123!",
    "host": "mydb.internal",
}
response = client.create_secret(
    Name="app/database_creds",
    Description="Application DB Credentials",
    SecretString=json.dumps(payload),
)

print(f"Created secret ARN: {response['ARN']}")


Step 5: Run the code

python3 fetch.py

{'Test': 'This is secret'}

Step 5: Lab Teardown & Cost Management

AWS Secrets Manager incurs $0.40/secret/month (prorated hourly). To prevent ongoing charges after completing lab tests, force-delete the secret without entering the default recovery retention period: