AWS Certified DevOps Engineer – ProfessionalConfiguration Management and Infrastructure as CodeMedium

A development team is using AWS CloudFormation to provision an Amazon RDS database. The database requires an administrator password that must be generated dynamically at deployment time, stored securely, and automatically rotated periodically. The team wants to avoid hardcoding the password in the CloudFormation template or passing it directly as a plaintext parameter. How can they achieve this using CloudFormation with secure secrets management best practices?

  1. AIntegrate AWS Secrets Manager with CloudFormation to generate, store, and rotate the password.
  2. BStore the password in an encrypted SSM Parameter Store parameter and reference it in the template.
  3. CUse a custom resource backed by a Lambda function to generate and store the password in an S3 bucket.
  4. DPass the password as a `NoEcho` CloudFormation parameter.
Show answer & explanation

Correct answer: A. Integrate AWS Secrets Manager with CloudFormation to generate, store, and rotate the password.

Integrating AWS Secrets Manager with CloudFormation is the recommended best practice for this scenario. Secrets Manager can automatically generate strong, unique passwords for RDS, store them securely, and automatically rotate them according to a defined schedule. CloudFormation can then reference the Secret ARN, ensuring the password is never exposed in plaintext in templates or logs and is managed securely throughout its lifecycle.

Why the other options are wrong

  • B. While SSM Parameter Store (SecureString) can store encrypted passwords, it does not natively support dynamic generation and automatic rotation of database credentials, which are key requirements.
  • C. A custom Lambda resource for this purpose would be an overly complex and less secure solution compared to using a dedicated secrets management service like Secrets Manager.
  • D. `NoEcho` only masks the parameter value in logs; it does not secure the password at rest, generate it dynamically, or handle rotation.

Secrets Manager with CloudFormation

AWS Secrets Manager can be integrated with CloudFormation to securely manage, rotate, and retrieve sensitive information like database credentials, preventing hardcoding and enhancing security.

  • Dynamically generates and stores secrets.
  • Automates secret rotation.
  • CloudFormation references secrets securely by ARN.

Memory trick: Secrets Manager is the master key that generates, locks, and changes itself.

More Configuration Management and Infrastructure as Code questions