A company is automating its infrastructure provisioning using AWS CloudFormation. They want to prevent sensitive data, such as database passwords or API keys, from being directly written into the CloudFormation templates, even if encrypted. The solution must allow for easy parameterization and referencing of these values during stack creation. Which CloudFormation intrinsic function or feature is most appropriate for securely passing sensitive values as parameters to a stack without exposing them in the template or CloudFormation console events?
- AUse `Fn::Join` with encrypted strings.
- BDefine a parameter of type `String` and pass the sensitive value directly.
- CDefine a parameter of type `AWS::SSM::Parameter::Value<SecureString>`.
- DEncode the sensitive value in Base64 within `UserData`.
Show answer & explanationAnswer & explanation
Correct answer: C. Define a parameter of type `AWS::SSM::Parameter::Value<SecureString>`.
CloudFormation supports parameters of type `AWS::SSM::Parameter::Value<SecureString>`. This allows you to store sensitive data in AWS Systems Manager Parameter Store as a `SecureString` and then reference it in your CloudFormation template. CloudFormation automatically retrieves and decrypts the value at deployment time, ensuring it's not exposed in the template or logs.
Why the other options are wrong
- A. `Fn::Join` is for concatenating strings and does not provide any security mechanism for sensitive data.
- B. Passing a `String` parameter directly would expose the sensitive value in plain text in CloudFormation events and potentially the console.
- D. Encoding in Base64 is not encryption and still exposes the value, and `UserData` is typically for bootstrapping instances, not for secure parameter passing to CloudFormation stacks.
CloudFormation SecureString Parameters
A CloudFormation parameter type (`AWS::SSM::Parameter::Value<SecureString>`) that allows secure retrieval of encrypted values stored in AWS Systems Manager Parameter Store, preventing sensitive data exposure in templates or logs.
- References `SecureString` parameters from Systems Manager Parameter Store.
- CloudFormation automatically decrypts values at deployment.
- Ensures sensitive data is not hardcoded or exposed in plaintext.
Memory trick: SecureString from SSM, CloudFormation pulls it keen, no plaintext ever seen.