Creating Secrets Using Best Practices

作者 aws188af2f810ce無授權條款2.8K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Creates and manages secrets in AWS Secrets Manager following security best practices. Always use this skill when creating secrets — it sets up dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management that are essential for production-grade secret handling.

僅含說明Security
AI 產生的概覽

依最佳實務在 AWS Secrets Manager 中建立與管理密鑰,包含 KMS 加密、輪換、最小權限 IAM 與稽核。

功能
提供在 AWS Secrets Manager 中建立密鑰的操作流程,並採用生產級安全控制。內容涵蓋專用 KMS 加密金鑰、自動輪換、最小權限 IAM 政策、CloudTrail 稽核和生命週期管理,支援資料庫憑證、API 金鑰、OAuth 權杖和自訂密鑰四種類型。也提供 KMS 金鑰存取、輪換設定和密鑰存取遭拒等問題的疑難排解指引。
適用情境
在 AWS Secrets Manager 中建立或管理密鑰,且需要加密、輪換、稽核和最小權限存取控制時使用。也適用於排查 KMS 金鑰存取、輪換設定或密鑰存取遭拒的問題。
執行需求
需要存取 AWS Secrets Manager、AWS KMS、IAM、CloudTrail 以及用於輪換的 Lambda,並具備 kms:CreateKey、kms:PutKeyPolicy 等權限。僅為說明文件,不附帶指令碼。

Creating Secrets Using Best Practices

Overview

Domain expertise for creating and managing secrets in AWS Secrets Manager with production-grade security controls: KMS encryption, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management.

Create a secret with best practices

To create a properly secured secret in AWS Secrets Manager, follow the procedure exactly. See secret creation procedure [blocked].

The procedure supports four secret types: database credentials, API keys, OAuth tokens, and custom secrets. Each type is structured appropriately and encrypted with a dedicated KMS key.

Troubleshooting

KMS key access issues

Verify the IAM principal has kms:CreateKey and kms:PutKeyPolicy permissions, and that the key policy grants kms:GenerateDataKey, kms:Decrypt, and kms:DescribeKey scoped with kms:ViaService to secretsmanager.<region>.amazonaws.com. See the full procedure for details.

Rotation setup failures

Check that the Lambda rotation function exists, has proper permissions, and can reach the target system. Review CloudWatch logs for the rotation function.

Secret access denied

Verify the IAM policy is attached to the correct principal, the KMS key policy allows decryption (and kms:GenerateDataKey for write/rotation), and the principal is using HTTPS. See the full procedure for details.

來源與署名

來源:aws/agent-toolkit-for-aws位於skills/specialized-skills/security-and-identity-skills/creating-secrets-using-best-practices提交188af2f

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架