Creating Secrets Using Best Practices

作者 aws188af2f810ce无许可证2.8K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Creates and manages secrets in AWS Secrets Manager following security best practices. Always use this skill when creating secrets — it sets up dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management that are essential for production-grade secret handling.

仅含说明Security
AI 生成的概览

按照最佳实践在 AWS Secrets Manager 中创建和管理密钥,包含 KMS 加密、轮换、最小权限 IAM 与审计。

功能
提供在 AWS Secrets Manager 中创建密钥的操作流程,并采用生产级安全控制。内容涵盖专用 KMS 加密密钥、自动轮换、最小权限 IAM 策略、CloudTrail 审计和生命周期管理,支持数据库凭据、API 密钥、OAuth 令牌和自定义密钥四种类型。还提供 KMS 密钥访问、轮换配置和密钥访问被拒等问题的排查指引。
适用场景
在 AWS Secrets Manager 中创建或管理密钥,并需要加密、轮换、审计和最小权限访问控制时使用。也适用于排查 KMS 密钥访问、轮换配置或密钥访问被拒的问题。
运行要求
需要访问 AWS Secrets Manager、AWS KMS、IAM、CloudTrail 以及用于轮换的 Lambda,并具备 kms:CreateKey、kms:PutKeyPolicy 等权限。仅为说明文档,不附带脚本。

Creating Secrets Using Best Practices

Overview

Domain expertise for creating and managing secrets in AWS Secrets Manager with production-grade security controls: KMS encryption, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management.

Create a secret with best practices

To create a properly secured secret in AWS Secrets Manager, follow the procedure exactly. See secret creation procedure [blocked].

The procedure supports four secret types: database credentials, API keys, OAuth tokens, and custom secrets. Each type is structured appropriately and encrypted with a dedicated KMS key.

Troubleshooting

KMS key access issues

Verify the IAM principal has kms:CreateKey and kms:PutKeyPolicy permissions, and that the key policy grants kms:GenerateDataKey, kms:Decrypt, and kms:DescribeKey scoped with kms:ViaService to secretsmanager.<region>.amazonaws.com. See the full procedure for details.

Rotation setup failures

Check that the Lambda rotation function exists, has proper permissions, and can reach the target system. Review CloudWatch logs for the rotation function.

Secret access denied

Verify the IAM policy is attached to the correct principal, the KMS key policy allows decryption (and kms:GenerateDataKey for write/rotation), and the principal is using HTTPS. See the full procedure for details.

来源与署名

来源:aws/agent-toolkit-for-aws位于skills/specialized-skills/security-and-identity-skills/creating-secrets-using-best-practices提交188af2f

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架