creating-secrets-using-best-practices

von aws

Erstellt und verwaltet Secrets in AWS Secrets Manager gemäß den Sicherheits-Best-Practices. Verwenden Sie diese Skill immer beim Erstellen von Secrets – sie richtet dedizierte KMS…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill creating-secrets-using-best-practices

Creating Secrets Using Best Practices

Overview

Domain expertise for creating and managing secrets in AWS Secrets Manager with production-grade security controls: KMS encryption, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management.

Create a secret with best practices

To create a properly secured secret in AWS Secrets Manager, follow the procedure exactly. See secret creation procedure.

The procedure supports four secret types: database credentials, API keys, OAuth tokens, and custom secrets. Each type is structured appropriately and encrypted with a dedicated KMS key.

Troubleshooting

KMS key access issues

Verify the IAM principal has kms:CreateKey and kms:PutKeyPolicy permissions, and that the key policy grants kms:GenerateDataKey, kms:Decrypt, and kms:DescribeKey scoped with kms:ViaService to secretsmanager.<region>.amazonaws.com. See the full procedure for details.

Rotation setup failures

Check that the Lambda rotation function exists, has proper permissions, and can reach the target system. Review CloudWatch logs for the rotation function.

Secret access denied

Verify the IAM policy is attached to the correct principal, the KMS key policy allows decryption (and kms:GenerateDataKey for write/rotation), and the principal is using HTTPS. See the full procedure for details.

Mehr Skills von aws

analyzing-release-readiness
aws
Löse eine Pre-Merge-Release-Bereitschaftsprüfung für einen GitHub-PR, GitLab-MR oder lokalen Branch aus. Verwende dies, wenn der Benutzer Codeänderungen auf Risiko, Korrektheit, … analysieren möchte.
scanning-with-aws-security-agent
aws
Führen Sie einen AWS Security Agent-Scan im Workspace durch – lädt die Quelle zu AWS hoch, scannt sie mit dem verwalteten Security Agent-Dienst und gibt bewertete, verifizierte… zurück.
coordinating-multi-space-devops-agent
aws
Koordiniere den AWS DevOps Agent über mehrere AgentSpaces hinweg aus einer einzigen Claude Code-Sitzung — leite Fragen an den richtigen Space weiter (prod vs. staging vs. Wissen), …
aws-security
aws
Behandelt AWS-Sicherheitsdienste und -Workflows – Security Hub V2 (OCSF)-Findings, Connectors, Aggregatoren, Automatisierungsregeln und Sicherheitsstatus-Zusammenfassungen;…
querying-aws-sagemaker-catalog
aws
Führt SQL-Analysen auf SageMaker Catalog-Asset-Metadaten-Tabellen aus, die als Apache Iceberg in S3 Tables exportiert wurden. Umfasst Governance-Abfragen, Asset-Wachstumsverfolgung, …
agents-connect
aws
Verwenden Sie dies, wenn Sie Ihren Agenten über Gateway mit externen APIs, Tools oder Diensten verbinden oder den Toolzugriff mit Cedar-Richtlinien einschränken. Behandelt Gateway-Einrichtung, Ziel…
aurora-dsql
aws
Stellt Aurora-DSQL-Cluster bereit und verwaltet sie, verbindet sich über psql oder DSQL-Connectors, verwaltet Schemas, führt Abfragen aus, migriert von MySQL, diagnostiziert Abfragepläne, …
transitgateway
aws
Konfiguriert AWS Transit Gateway: Erstellen eines Hubs und Anbinden von VPCs, Segmentieren von Traffic mit Routentabellen, Zentralisieren von Egress und Inspection über einen Hub…