Creating Secrets Using Best Practices

by aws188af2f810ceNo license2.8K starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated today

Creates and manages secrets in AWS Secrets Manager following security best practices. Always use this skill when creating secrets — it sets up dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management that are essential for production-grade secret handling.

Instructions onlySecurity
AI-generated overview

Creates and manages AWS Secrets Manager secrets with KMS encryption, rotation, least-privilege IAM, and auditing.

What it does
Provides a procedure for creating secrets in AWS Secrets Manager with production-grade controls. It covers dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management for database credentials, API keys, OAuth tokens, and custom secrets. It also gives troubleshooting guidance for KMS key access, rotation setup, and secret access failures.
When to use it
Use when creating or managing secrets in AWS Secrets Manager and you need them encrypted, rotated, audited, and governed by least-privilege access. Also use when diagnosing KMS key access, rotation setup, or secret access denied problems.
Requirements
Requires access to AWS Secrets Manager, AWS KMS, IAM, CloudTrail, and Lambda for rotation, plus permissions such as kms:CreateKey and kms:PutKeyPolicy. Instructions only; no scripts are shipped.

Creating Secrets Using Best Practices

Overview

Domain expertise for creating and managing secrets in AWS Secrets Manager with production-grade security controls: KMS encryption, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management.

Create a secret with best practices

To create a properly secured secret in AWS Secrets Manager, follow the procedure exactly. See secret creation procedure [blocked].

The procedure supports four secret types: database credentials, API keys, OAuth tokens, and custom secrets. Each type is structured appropriately and encrypted with a dedicated KMS key.

Troubleshooting

KMS key access issues

Verify the IAM principal has kms:CreateKey and kms:PutKeyPolicy permissions, and that the key policy grants kms:GenerateDataKey, kms:Decrypt, and kms:DescribeKey scoped with kms:ViaService to secretsmanager.<region>.amazonaws.com. See the full procedure for details.

Rotation setup failures

Check that the Lambda rotation function exists, has proper permissions, and can reach the target system. Review CloudWatch logs for the rotation function.

Secret access denied

Verify the IAM policy is attached to the correct principal, the KMS key policy allows decryption (and kms:GenerateDataKey for write/rotation), and the principal is using HTTPS. See the full procedure for details.

Source and attribution

Source:aws/agent-toolkit-for-awsinskills/specialized-skills/security-and-identity-skills/creating-secrets-using-best-practicesat commit188af2f

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal