Cybersecurity/AWS Cybersecurity papers/AWS Secrets Example: Difference between revisions

From Cramsession
Jump to navigationJump to search
✍️ Verified Author: Mflavell • Click to view professional profile & credentials
Line 46: Line 46:


==== 1. Verify IMDSv2 Credential Acquisition ====
==== 1. Verify IMDSv2 Credential Acquisition ====
lets do this on Amazon Linuz - Much easier!
lets do this on Amazon Linux - Much easier!


Install python:
'''Install python:'''
  sudo dnf update -y
  sudo dnf update -y
  sudo dnf install -y python3 python3-pip
  sudo dnf install -y python3 python3-pip
Line 54: Line 54:
  pip3 --version
  pip3 --version


 
'''<br />Create the v-env:'''
Crearte the v-env:


  mkdir ~/secrets-lab && cd ~/secrets-lab
  mkdir ~/secrets-lab && cd ~/secrets-lab

Revision as of 21:34, 6 October 2026

AWS Secrets Manager Retrieval on EC2 via IAM Instance Profiles

Overview

Storing secrets outside of source code and configuration files is a conerstone of cybersecurity. Fortunatley AWS includeds "AWS Secrets Manger" intended for this purpose.


Some of the KEY features of AWS Secrets manager are:

  • Granular access controls
  • Auduable access (Know who, what and when)
  • Secret history
  • Seemless intergration with AWS services
  • Regional replication


This paper provides a demonstration of securing secrets with AWS Serets manager.

Step 1: Create the secret

  1. From AWS console open secerts manager.
  2. Select Other type of secret
  3. Use the "Key / Value" Option
  4. Provice and key and a value
  5. Click next
  6. Provice a name for the secret
  7. Click next
  8. Turn on (or off) automatic rotation
  9. Click next
  10. Click store


Great! Now we have a secret!. However nothing will work without IAM permissions!

Step 2: Configure IAM Permissions and Instance Profile

  1. Open EC2, Select Instances
  2. Open your sandbox EC2 instance
  3. Select Actions > Security > Modift IAM Role
  4. Select "Create IAM Role"
  5. Let's call the role "Secret_read"
  6. Select "Use Existing Policy"
  7. Select "AWSSecretsManagerClientReadOnlyAccess"
  8. Select "Create Role"

Step 3: Setup the sandbox

1. Verify IMDSv2 Credential Acquisition

lets do this on Amazon Linux - Much easier!

Install python:

sudo dnf update -y
sudo dnf install -y python3 python3-pip
python3 --version
pip3 --version


Create the v-env:

mkdir ~/secrets-lab && cd ~/secrets-lab
python3 -m venv venv
source venv/bin/activate
pip install --upgrade pip
pip install boto3

Step 4: Create the code

Create the test code, fetch.py

import json
import boto3

client = boto3.client("secretsmanager", region_name="us-east-1")

payload = {
    "username": "db_admin",
    "password": "SuperSecretPassword123!",
    "host": "mydb.internal",
}
response = client.create_secret(
    Name="app/database_creds",
    Description="Application DB Credentials",
    SecretString=json.dumps(payload),
)

print(f"Created secret ARN: {response['ARN']}")

Step 5: Run the code

python3 fetch.py

{'Test': 'This is secret'}

Step 5: Lab Teardown & Cost Management

AWS Secrets Manager incurs $0.40/secret/month (prorated hourly). To prevent ongoing charges after completing lab tests, force-delete the secret without entering the default recovery retention period: