AWS Certified DevOps Engineer – ProfessionalSDLC AutomationEasy
A DevOps team is responsible for managing application configurations and secrets across multiple environments (development, staging, production) for a new microservice. They need a secure, centralized, and version-controlled way to store database connection strings, API keys, and other sensitive parameters, ensuring that these are only accessible by authorized services and users. Which AWS service is best suited for this requirement?
- AUsing AWS Secrets Manager to store and retrieve secrets.
- BEncrypting secrets in Amazon S3 buckets and managing access via bucket policies.
- CStoring secrets directly in environment variables within AWS Lambda functions.
- DHardcoding secrets within the application's source code and encrypting the Git repository.
Show answer & explanationAnswer & explanation
Correct answer: A. Using AWS Secrets Manager to store and retrieve secrets.
AWS Secrets Manager is specifically designed for securely storing and managing secrets like database credentials, API keys, and other sensitive data. It offers features like automatic rotation, fine-grained access control, and integration with other AWS services, making it ideal for this scenario.
Why the other options are wrong
- B. Storing encrypted secrets in S3 is possible but requires a custom solution for decryption, access management, and rotation, which is more complex and less secure than using a purpose-built service like Secrets Manager.
- C. While possible for Lambda, environment variables are not ideal for sensitive data as they are not encrypted at rest by default and lack advanced management features like rotation or versioning.
- D. Hardcoding secrets is a severe security anti-pattern. Even with repository encryption, secrets become part of the codebase, are difficult to rotate, and pose a significant security risk.
AWS Secrets Manager
An AWS service that helps you protect access to your applications, services, and IT resources by easily rotating, managing, and retrieving database credentials, API keys, and other secrets throughout their lifecycle.
- Securely stores and retrieves sensitive data.
- Supports automatic secret rotation.
- Integrates with IAM for fine-grained access control.
Memory trick: For secrets, trust the Manager; don't hide them in the code or environment.