AWS Certified DevOps Engineer – ProfessionalSecurity and ComplianceEasy
A DevOps team is deploying a new containerized application to Amazon ECS. The application needs to securely fetch sensitive configuration parameters and credentials at runtime without embedding them directly into the container images or environment variables. The team wants to ensure that these secrets are retrieved from a centralized, secure store and are only accessible by authorized tasks. Which AWS service should the team use to store and retrieve these secrets?
- AAWS Key Management Service (KMS)
- BAWS Systems Manager Parameter Store
- CAmazon S3
- DAWS Secrets Manager
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Secrets Manager
AWS Secrets Manager is specifically designed for storing and managing secrets such as database credentials, API keys, and other sensitive information. It integrates well with ECS and allows for automatic rotation of secrets, making it ideal for this scenario.
Why the other options are wrong
- A. AWS Key Management Service (KMS) is used for creating and managing cryptographic keys, not for storing application secrets directly.
- B. AWS Systems Manager Parameter Store can store secrets, but AWS Secrets Manager offers additional features like automatic rotation and more robust integration with services for secret retrieval.
- C. Amazon S3 is an object storage service and is not primarily designed for secure, programmatic retrieval of individual secrets at runtime.
AWS Secrets Manager
A service that helps you protect access to your applications, services, and IT resources by rotating, managing, and retrieving database credentials, API keys, and other secrets throughout their lifecycle.
- Automatically rotates secrets.
- Securely stores and retrieves secrets.
- Integrates with other AWS services like ECS and Lambda.
Memory trick: Secrets Manager: The vault for your application's hidden treasures.