AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeMedium

A security-conscious organization is implementing a new CI/CD pipeline. They need to ensure that no hardcoded credentials or sensitive information are committed to their source code repositories. The pipeline should automatically scan code for these patterns before deployment. Which best practice should they implement, and what tool could assist in this process?

  1. AUse environment variables for secrets during runtime; manually review pull requests.
  2. BStore all credentials in a private S3 bucket; grant temporary access during builds.
  3. CImplement a pre-commit hook with a secret scanning tool; store secrets in AWS Secrets Manager.
  4. DEncrypt the entire source code repository; decrypt only at deployment time.
Show answer & explanation

Correct answer: C. Implement a pre-commit hook with a secret scanning tool; store secrets in AWS Secrets Manager.

Implementing pre-commit hooks with secret scanning tools (e.g., Git-Secrets, TruffleHog) prevents sensitive information from being committed. Storing actual secrets in AWS Secrets Manager ensures they are never hardcoded and are retrieved securely at runtime.

Why the other options are wrong

  • A. While environment variables are good for runtime, manual review is error-prone and doesn't prevent accidental commits to history.
  • B. Storing credentials in S3 is not the primary secure secret management solution; AWS Secrets Manager is purpose-built for this with rotation and fine-grained access.
  • D. Encrypting the entire repository is overly complex and does not solve the problem of hardcoded secrets within the code before encryption.

Secrets in Code Prevention

The practice of ensuring that no sensitive information (e.g., API keys, passwords, private keys) is hardcoded or accidentally committed into source code repositories.

  • Uses secret scanning tools (e.g., Git-Secrets, TruffleHog).
  • Integrates into CI/CD pipelines and pre-commit hooks.
  • Complements secure secret storage solutions like AWS Secrets Manager.

Memory trick: Scan pre-commit, secrets out of sight, Manager keeps them safe and tight.

More Configuration Management and Infrastructure as Code questions