AWS Certified DevOps Engineer – ProfessionalSDLC AutomationMedium

A financial institution requires that all application configurations, including database connection strings and API keys, are securely managed and rotated automatically. They are using AWS CodePipeline for their CI/CD and AWS Lambda for their serverless applications. How can the DevOps team integrate secure configuration management and rotation into their pipeline?

  1. AStore configurations in environment variables within the Lambda function code and manually rotate them.
  2. BUse AWS Secrets Manager to store and rotate secrets, retrieving them at runtime in Lambda.
  3. CEmbed encrypted configuration files directly into the application's deployment package.
  4. DEncrypt configurations using KMS and store them in S3, updating them via CodePipeline.
Show answer & explanation

Correct answer: B. Use AWS Secrets Manager to store and rotate secrets, retrieving them at runtime in Lambda.

AWS Secrets Manager is designed for storing, managing, and automatically rotating secrets like database credentials and API keys. Lambda functions can retrieve these secrets at runtime, ensuring they are never hardcoded or exposed in the deployment package.

Why the other options are wrong

  • A. Environment variables are not secure for sensitive data and manual rotation is error-prone and not scalable.
  • C. Embedding secrets, even encrypted, increases the risk of exposure and complicates rotation.
  • D. While S3 can store encrypted data, it lacks automatic rotation and built-in runtime retrieval for secrets.

AWS Secrets Manager Integration

A service that helps you protect access to your applications, services, and IT resources by enabling you to easily rotate, manage, and retrieve database credentials, API keys, and other secrets throughout their lifecycle.

  • Stores secrets securely with encryption.
  • Supports automatic rotation of secrets for various services.
  • Secrets can be retrieved programmatically at runtime.
  • Integrates with AWS services like Lambda and RDS.

Memory trick: Secrets Manager: The vault that spins keys for you.

More SDLC Automation questions