How to manage any kind of secret with AWS Secrets Manager
sanderknape.com
sanderknape.com
RDS rotation is...fine, I guess, if you have an auditor who really wants that and can't write a scheduled job for the task (I've been using one with credstash so long it's just an automatic part of a new environment), but it's got me skeptical.
Something AWS could do, and I'd be very interested in, is a hosted moral equivalent to Vault. Give me a daemon or something to run on an instance, allow me to IAM-gate temporary SSH credentials (and chuck it in CloudTrail) and temporary SQL databases, and that I'd pay for 'cause I really don't want to deal with Vault or HashiCorp. But AWS Secrets Manager, by itself, doesn't really present a good reason-for-being to me.
No open source product will meet the requirement, because you often need FIPS validated crypto.
What do you mean? Redhat has FIPS mode. Openssl has FIPS object module. You can create a secrets storage product out of those blocks. Do you mean some specific requirements for the project you were working on?
You need to have a Dev who understands and documents everything, your ops guys need to be careful to not fix a security bug in OpenSSL that leaves you with a non-validated version, etc.
Or you can give AWS $5/secret/year. It’s the path of least resistance.
If I need to sit, I need a chair can support my weight. A box containing 2x4s, a hammer and box of nails doesn’t meet the need.
I’m not disparaging OSS — it just isn’t a good fit for use cases like this when you need to deal with bullshit like FIPS 140-2.
That said, there are a handful of examples available to handle RDS secret rotation through parameter store with Lambdas and custom cloudformation resources.
https://docs.aws.amazon.com/kms/latest/developerguide/servic...
I was confused by the naming convention at launch, but a secret is a set of key value pairs and not a single key value pair.
Which is what we are comparing here. Enterprise with enterprise. Features equivalency.
Additionally they might just retire it in favour of the secrets manager soon anyway. I bet the pricing on that would drop at that point too
Parameter Store isn’t going away and is still under active development.