Cybersecurity/AWS Cybersecurity papers/AWS Secrets Example: Difference between revisions
From Cramsession
Jump to navigationJump to search
✍️ Verified Author: Mflavell • Click to view professional profile & credentials
| Line 50: | Line 50: | ||
Install python: | Install python: | ||
sudo dnf update -y | sudo dnf update -y | ||
sudo dnf install -y python3 python3-pip | sudo dnf install -y python3 python3-pip | ||
python3 --version | python3 --version | ||
pip3 --version | pip3 --version | ||
| Line 61: | Line 58: | ||
mkdir ~/secrets-lab && cd ~/secrets-lab | mkdir ~/secrets-lab && cd ~/secrets-lab | ||
python3 -m venv venv | python3 -m venv venv | ||
source venv/bin/activate | source venv/bin/activate | ||
pip install --upgrade pip | pip install --upgrade pip | ||
pip install boto3 | pip install boto3 | ||
| Line 73: | Line 66: | ||
Create the test code, fetch.py | Create the test code, fetch.py | ||
import json | import json | ||
import boto3 | import boto3 | ||
client = boto3.client("secretsmanager", region_name="us-east-1") | client = boto3.client("secretsmanager", region_name="us-east-1") | ||
payload = { | payload = { | ||
"username": "db_admin", | "username": "db_admin", | ||
"password": "SuperSecretPassword123!", | "password": "SuperSecretPassword123!", | ||
"host": "mydb.internal", | "host": "mydb.internal", | ||
} | } | ||
response = client.create_secret( | response = client.create_secret( | ||
Name="app/database_creds", | Name="app/database_creds", | ||
Description="Application DB Credentials", | Description="Application DB Credentials", | ||
SecretString=json.dumps(payload), | SecretString=json.dumps(payload), | ||
) | ) | ||
print(f"Created secret ARN: {response['ARN']}") | print(f"Created secret ARN: {response['ARN']}") | ||
==== Step 5: Run the code ==== | ==== Step 5: Run the code ==== | ||
python3 fetch.py | python3 fetch.py | ||
{'Test': 'This is secret'} | {'Test': 'This is secret'} | ||
==== Step 5: Lab Teardown & Cost Management ==== | ==== Step 5: Lab Teardown & Cost Management ==== | ||
AWS Secrets Manager incurs $0.40/secret/month (prorated hourly). To prevent ongoing charges after completing lab tests, force-delete the secret without entering the default recovery retention period: | AWS Secrets Manager incurs $0.40/secret/month (prorated hourly). To prevent ongoing charges after completing lab tests, force-delete the secret without entering the default recovery retention period: | ||
Revision as of 21:33, 6 October 2026
AWS Secrets Manager Retrieval on EC2 via IAM Instance Profiles
Overview
Storing secrets outside of source code and configuration files is a conerstone of cybersecurity. Fortunatley AWS includeds "AWS Secrets Manger" intended for this purpose.
Some of the KEY features of AWS Secrets manager are:
- Granular access controls
- Auduable access (Know who, what and when)
- Secret history
- Seemless intergration with AWS services
- Regional replication
This paper provides a demonstration of securing secrets with AWS Serets manager.
Step 1: Create the secret
- From AWS console open secerts manager.
- Select Other type of secret
- Use the "Key / Value" Option
- Provice and key and a value
- Click next
- Provice a name for the secret
- Click next
- Turn on (or off) automatic rotation
- Click next
- Click store
Great! Now we have a secret!. However nothing will work without IAM permissions!
Step 2: Configure IAM Permissions and Instance Profile
- Open EC2, Select Instances
- Open your sandbox EC2 instance
- Select Actions > Security > Modift IAM Role
- Select "Create IAM Role"
- Let's call the role "Secret_read"
- Select "Use Existing Policy"
- Select "AWSSecretsManagerClientReadOnlyAccess"
- Select "Create Role"
Step 3: Setup the sandbox
1. Verify IMDSv2 Credential Acquisition
lets do this on Amazon Linuz - Much easier!
Install python:
sudo dnf update -y sudo dnf install -y python3 python3-pip python3 --version pip3 --version
Crearte the v-env:
mkdir ~/secrets-lab && cd ~/secrets-lab python3 -m venv venv source venv/bin/activate pip install --upgrade pip pip install boto3
Step 4: Create the code
Create the test code, fetch.py
import json
import boto3
client = boto3.client("secretsmanager", region_name="us-east-1")
payload = {
"username": "db_admin",
"password": "SuperSecretPassword123!",
"host": "mydb.internal",
}
response = client.create_secret(
Name="app/database_creds",
Description="Application DB Credentials",
SecretString=json.dumps(payload),
)
print(f"Created secret ARN: {response['ARN']}")
Step 5: Run the code
python3 fetch.py
{'Test': 'This is secret'}
Step 5: Lab Teardown & Cost Management
AWS Secrets Manager incurs $0.40/secret/month (prorated hourly). To prevent ongoing charges after completing lab tests, force-delete the secret without entering the default recovery retention period: