creating-secrets-using-best-practices

โดย aws

สร้างและจัดการ secrets ใน AWS Secrets Manager ตามแนวทางปฏิบัติด้านความปลอดภัยที่ดีที่สุด ใช้ทักษะนี้เสมอเมื่อสร้าง secrets — ทักษะนี้จะตั้งค่า KMS เฉพาะ...

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill creating-secrets-using-best-practices

Creating Secrets Using Best Practices

Overview

Domain expertise for creating and managing secrets in AWS Secrets Manager with production-grade security controls: KMS encryption, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management.

Create a secret with best practices

To create a properly secured secret in AWS Secrets Manager, follow the procedure exactly. See secret creation procedure.

The procedure supports four secret types: database credentials, API keys, OAuth tokens, and custom secrets. Each type is structured appropriately and encrypted with a dedicated KMS key.

Troubleshooting

KMS key access issues

Verify the IAM principal has kms:CreateKey and kms:PutKeyPolicy permissions, and that the key policy grants kms:GenerateDataKey, kms:Decrypt, and kms:DescribeKey scoped with kms:ViaService to secretsmanager.<region>.amazonaws.com. See the full procedure for details.

Rotation setup failures

Check that the Lambda rotation function exists, has proper permissions, and can reach the target system. Review CloudWatch logs for the rotation function.

Secret access denied

Verify the IAM policy is attached to the correct principal, the KMS key policy allows decryption (and kms:GenerateDataKey for write/rotation), and the principal is using HTTPS. See the full procedure for details.

Skills เพิ่มเติมจาก aws

analyzing-release-readiness
aws
เรียกใช้การตรวจสอบความพร้อมก่อนการรวมโค้ด (pre-merge release readiness review) บน GitHub PR, GitLab MR หรือสาขาในเครื่อง (local branch) ใช้เมื่อผู้ใช้ต้องการวิเคราะห์การเปลี่ยนแปลงโค้ดเพื่อหาความเสี่ยง ความถูกต้อง…
scanning-with-aws-security-agent
aws
รันการสแกน AWS Security Agent บนเวิร์กสเปซ — อัปโหลดซอร์สไปยัง AWS สแกนด้วยบริการ Security Agent ที่มีการจัดการ และส่งคืนผลลัพธ์ที่จัดอันดับและตรวจสอบแล้ว…
coordinating-multi-space-devops-agent
aws
ประสานงาน AWS DevOps Agent ในหลาย AgentSpaces จากเซสชัน Claude Code เดียว — กำหนดเส้นทางคำถามไปยังพื้นที่ที่ถูกต้อง (prod vs staging vs knowledge),…
aws-security
aws
ครอบคลุมบริการและเวิร์กโฟลว์ด้านความปลอดภัยของ AWS — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules และสรุปสถานะความปลอดภัย;…
querying-aws-sagemaker-catalog
aws
รันการวิเคราะห์ SQL บนตารางเมตาดาต้าของสินทรัพย์ SageMaker Catalog ที่ส่งออกเป็น Apache Iceberg ใน S3 Tables ครอบคลุมการสอบถามด้านธรรมาภิบาล การติดตามการเติบโตของสินทรัพย์…
agents-connect
aws
ใช้เมื่อเชื่อมต่อเอเจนต์ของคุณกับ API เครื่องมือ หรือบริการภายนอกผ่าน Gateway หรือจำกัดการเข้าถึงเครื่องมือด้วยนโยบาย Cedar จัดการการตั้งค่า Gateway เป้าหมาย…
aurora-dsql
aws
จัดเตรียมและจัดการคลัสเตอร์ Aurora DSQL เชื่อมต่อผ่าน psql หรือ DSQL Connectors จัดการสคีมา รันคิวรี ย้ายข้อมูลจาก MySQL วินิจฉัยแผนคิวรี…
transitgateway
aws
กำหนดค่า AWS Transit Gateway: สร้างฮับและเชื่อมต่อ VPC แบ่งกลุ่มทราฟฟิกด้วยตารางเส้นทาง รวมศูนย์อีเกรสและการตรวจสอบผ่านฮับ…