creating-secrets-using-best-practices

por aws

Crea y gestiona secretos en AWS Secrets Manager siguiendo las mejores prácticas de seguridad. Utiliza siempre esta habilidad al crear secretos: configura un KMS dedicado…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill creating-secrets-using-best-practices

Creating Secrets Using Best Practices

Overview

Domain expertise for creating and managing secrets in AWS Secrets Manager with production-grade security controls: KMS encryption, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management.

Create a secret with best practices

To create a properly secured secret in AWS Secrets Manager, follow the procedure exactly. See secret creation procedure.

The procedure supports four secret types: database credentials, API keys, OAuth tokens, and custom secrets. Each type is structured appropriately and encrypted with a dedicated KMS key.

Troubleshooting

KMS key access issues

Verify the IAM principal has kms:CreateKey and kms:PutKeyPolicy permissions, and that the key policy grants kms:GenerateDataKey, kms:Decrypt, and kms:DescribeKey scoped with kms:ViaService to secretsmanager.<region>.amazonaws.com. See the full procedure for details.

Rotation setup failures

Check that the Lambda rotation function exists, has proper permissions, and can reach the target system. Review CloudWatch logs for the rotation function.

Secret access denied

Verify the IAM policy is attached to the correct principal, the KMS key policy allows decryption (and kms:GenerateDataKey for write/rotation), and the principal is using HTTPS. See the full procedure for details.

Más skills de aws

analyzing-release-readiness
aws
Activa una revisión de preparación para el lanzamiento previa a la fusión en un PR de GitHub, MR de GitLab o rama local. Úsalo cuando el usuario quiera analizar cambios de código para evaluar riesgo, corrección,…
scanning-with-aws-security-agent
aws
Ejecuta un escaneo del AWS Security Agent en el workspace: sube el código fuente a AWS, lo escanea con el servicio administrado Security Agent y devuelve resultados clasificados y verificados…
coordinating-multi-space-devops-agent
aws
Coordina el agente DevOps de AWS a través de múltiples AgentSpaces desde una sola sesión de Claude Code: enruta las preguntas al espacio correcto (prod vs staging vs knowledge),…
aws-security
aws
Cubre los servicios y flujos de trabajo de seguridad de AWS: hallazgos de Security Hub V2 (OCSF), conectores, agregadores, reglas de automatización y resúmenes de postura de seguridad;…
querying-aws-sagemaker-catalog
aws
Ejecuta análisis SQL sobre tablas de metadatos de activos de SageMaker Catalog exportadas como Apache Iceberg en S3 Tables. Cubre consultas de gobernanza, seguimiento del crecimiento de activos,…
agents-connect
aws
Úsalo al conectar tu agente a APIs, herramientas o servicios externos a través de Gateway, o al restringir el acceso a herramientas con políticas de Cedar. Gestiona la configuración de gateway, target…
aurora-dsql
aws
Aprovisiona y gestiona clústeres de Aurora DSQL, se conecta mediante psql o conectores DSQL, gestiona esquemas, ejecuta consultas, migra desde MySQL, diagnostica planes de consulta,…
transitgateway
aws
Configura AWS Transit Gateway: creación de un hub y conexión de VPCs, segmentación del tráfico con tablas de rutas, centralización de la salida y la inspección a través de un hub…