creating-secrets-using-best-practices

द्वारा aws

AWS Secrets Manager में सुरक्षा सर्वोत्तम प्रथाओं का पालन करते हुए secrets बनाता और प्रबंधित करता है। Secrets बनाते समय हमेशा इस skill का उपयोग करें — यह समर्पित KMS…

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill creating-secrets-using-best-practices

Creating Secrets Using Best Practices

Overview

Domain expertise for creating and managing secrets in AWS Secrets Manager with production-grade security controls: KMS encryption, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management.

Create a secret with best practices

To create a properly secured secret in AWS Secrets Manager, follow the procedure exactly. See secret creation procedure.

The procedure supports four secret types: database credentials, API keys, OAuth tokens, and custom secrets. Each type is structured appropriately and encrypted with a dedicated KMS key.

Troubleshooting

KMS key access issues

Verify the IAM principal has kms:CreateKey and kms:PutKeyPolicy permissions, and that the key policy grants kms:GenerateDataKey, kms:Decrypt, and kms:DescribeKey scoped with kms:ViaService to secretsmanager.<region>.amazonaws.com. See the full procedure for details.

Rotation setup failures

Check that the Lambda rotation function exists, has proper permissions, and can reach the target system. Review CloudWatch logs for the rotation function.

Secret access denied

Verify the IAM policy is attached to the correct principal, the KMS key policy allows decryption (and kms:GenerateDataKey for write/rotation), and the principal is using HTTPS. See the full procedure for details.

aws की और Skills

analyzing-release-readiness
aws
प्री-मर्ज रिलीज़ तैयारी समीक्षा को GitHub PR, GitLab MR, या स्थानीय ब्रांच पर ट्रिगर करें। जब उपयोगकर्ता जोखिम, शुद्धता,… के लिए कोड परिवर्तनों का विश्लेषण करना चाहता है तब उपयोग करें।
scanning-with-aws-security-agent
aws
वर्कस्पेस पर AWS Security Agent स्कैन चलाएँ — स्रोत को AWS पर अपलोड करता है, प्रबंधित Security Agent सेवा से स्कैन करता है, और रैंक किए गए, सत्यापित… परिणाम लौटाता है।
coordinating-multi-space-devops-agent
aws
एक Claude Code सत्र से कई AgentSpaces में AWS DevOps Agent का समन्वय करें — प्रश्नों को सही स्थान (prod बनाम staging बनाम knowledge) पर भेजें,…
aws-security
aws
AWS सुरक्षा सेवाओं और वर्कफ़्लो को कवर करता है — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, और security posture summaries;…
querying-aws-sagemaker-catalog
aws
SageMaker Catalog एसेट मेटाडेटा टेबल्स पर SQL एनालिटिक्स चलाता है जिन्हें S3 Tables में Apache Iceberg के रूप में निर्यात किया गया है। इसमें गवर्नेंस क्वेरी, एसेट ग्रोथ ट्रैकिंग शामिल है…
agents-connect
aws
अपने एजेंट को Gateway के माध्यम से बाहरी APIs, टूल्स, या सेवाओं से जोड़ते समय, या Cedar नीतियों के साथ टूल एक्सेस प्रतिबंधित करते समय उपयोग करें। Gateway सेटअप, लक्ष्य…
aurora-dsql
aws
Aurora DSQL क्लस्टरों की प्रावधानिंग और प्रबंधन करता है, psql या DSQL कनेक्टर्स के माध्यम से जुड़ता है, स्कीमा प्रबंधित करता है, क्वेरी चलाता है, MySQL से माइग्रेट करता है, क्वेरी योजनाओं का निदान करता है,…
transitgateway
aws
AWS Transit Gateway कॉन्फ़िगर करता है: एक हब बनाना और VPCs को जोड़ना, रूट टेबल के साथ ट्रैफ़िक को विभाजित करना, एक हब के माध्यम से ईग्रेस और इंस्पेक्शन को केंद्रीकृत करना…