creating-secrets-using-best-practices

von aws

Creates and manages secrets in AWS Secrets Manager following security best practices. Always use this skill when creating secrets — it sets up dedicated KMS…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill creating-secrets-using-best-practices

Creating Secrets Using Best Practices

Overview

Domain expertise for creating and managing secrets in AWS Secrets Manager with production-grade security controls: KMS encryption, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management.

Create a secret with best practices

To create a properly secured secret in AWS Secrets Manager, follow the procedure exactly. See secret creation procedure.

The procedure supports four secret types: database credentials, API keys, OAuth tokens, and custom secrets. Each type is structured appropriately and encrypted with a dedicated KMS key.

Troubleshooting

KMS key access issues

Verify the IAM principal has kms:CreateKey and kms:PutKeyPolicy permissions, and that the key policy grants kms:GenerateDataKey, kms:Decrypt, and kms:DescribeKey scoped with kms:ViaService to secretsmanager.<region>.amazonaws.com. See the full procedure for details.

Rotation setup failures

Check that the Lambda rotation function exists, has proper permissions, and can reach the target system. Review CloudWatch logs for the rotation function.

Secret access denied

Verify the IAM policy is attached to the correct principal, the KMS key policy allows decryption (and kms:GenerateDataKey for write/rotation), and the principal is using HTTPS. See the full procedure for details.

Mehr Skills von aws

agents-build
aws
Use to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource…
official
agents-connect
aws
Verwenden Sie dies, wenn Sie Ihren Agenten über Gateway mit externen APIs, Tools oder Diensten verbinden oder den Toolzugriff mit Cedar-Richtlinien einschränken. Behandelt Gateway-Einrichtung, Ziel…
official
agents-debug
aws
Use when your agent or environment is broken — wrong answers, errors, timeouts, tool failures, or CLI issues. Reads traces and logs to diagnose root causes.…
official
agents-deploy
aws
Verwenden Sie dies beim Bereitstellen Ihres Agents auf AWS oder wenn eine Bereitstellung fehlgeschlagen ist. Behandelt Pre-Flight-Validierung, CDK/IAM/Quota-Fehlerdiagnose, Versionsverwaltung, Rollback,…
official
agents-get-started
aws
Verwenden Sie, wenn ein Entwickler ein neues Agent-Projekt erstellen oder mit AgentCore beginnen möchte. Behandelt Framework-Auswahl, Projekt-Gerüstbau, erste Bereitstellung und…
official
agents-harden
aws
Verwenden Sie dies, wenn Sie Ihren Agenten für die Produktion vorbereiten — IAM-Scoping, eingehende Authentifizierung (JWT, SigV4), Geheimnisverwaltung, Cold-Start-Optimierung, Sitzungslebenszyklus, Rate…
official
agents-pay
aws
Verwenden, wenn DIESER Agent zur Laufzeit für x402-geschützte Inhalte zahlen muss: eine Paywall mitten in der Aufgabe treffen, diese über AgentCore Payments abwickeln und anwenden…
official
amazon-aurora-mysql
aws
Amazon Aurora MySQL — creates, modifies, and advises on Aurora MySQL clusters specifically (MySQL-compatible engine, Aurora serverless, parallel query).…
official