creating-secrets-using-best-practices

โดย aws

สร้างและจัดการ secrets ใน AWS Secrets Manager ตามแนวทางปฏิบัติด้านความปลอดภัยที่ดีที่สุด ใช้ทักษะนี้เสมอเมื่อสร้าง secrets — ทักษะนี้จะตั้งค่า KMS เฉพาะ...

npx skills add https://github.com/aws/agent-toolkit-for-aws --skill creating-secrets-using-best-practices

Creating Secrets Using Best Practices

Overview

Domain expertise for creating and managing secrets in AWS Secrets Manager with production-grade security controls: KMS encryption, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management.

Create a secret with best practices

To create a properly secured secret in AWS Secrets Manager, follow the procedure exactly. See secret creation procedure.

The procedure supports four secret types: database credentials, API keys, OAuth tokens, and custom secrets. Each type is structured appropriately and encrypted with a dedicated KMS key.

Troubleshooting

KMS key access issues

Verify the IAM principal has kms:CreateKey and kms:PutKeyPolicy permissions, and that the key policy grants kms:GenerateDataKey, kms:Decrypt, and kms:DescribeKey scoped with kms:ViaService to secretsmanager.<region>.amazonaws.com. See the full procedure for details.

Rotation setup failures

Check that the Lambda rotation function exists, has proper permissions, and can reach the target system. Review CloudWatch logs for the rotation function.

Secret access denied

Verify the IAM policy is attached to the correct principal, the KMS key policy allows decryption (and kms:GenerateDataKey for write/rotation), and the principal is using HTTPS. See the full procedure for details.

Skills เพิ่มเติมจาก aws

agents-build
aws
ใช้เพื่อขยายโปรเจกต์ agent ที่มีอยู่ด้วย memory, การผสานรวมแอป, VPC, multi-agent, การย้ายระบบ, โมเดล, เบราว์เซอร์, code interpreter, การชำระเงิน หรือทรัพยากร…
official
agents-connect
aws
ใช้เมื่อเชื่อมต่อเอเจนต์ของคุณกับ API เครื่องมือ หรือบริการภายนอกผ่าน Gateway หรือจำกัดการเข้าถึงเครื่องมือด้วยนโยบาย Cedar จัดการการตั้งค่า Gateway เป้าหมาย…
official
agents-debug
aws
ใช้เมื่อเอเจนต์หรือสภาพแวดล้อมของคุณมีปัญหา เช่น คำตอบที่ผิด ข้อผิดพลาด หมดเวลา เครื่องมือล้มเหลว หรือปัญหา CLI อ่านเทรซและล็อกเพื่อวินิจฉัยสาเหตุต้นตอ…
official
agents-deploy
aws
ใช้เมื่อกำลัง部署เอเจนต์ของคุณไปยัง AWS หรือเมื่อการ部署ล้มเหลว จัดการการตรวจสอบก่อน部署 การวินิจฉัยข้อผิดพลาด CDK/IAM/โควตา การจัดการเวอร์ชัน การย้อนกลับ…
official
agents-get-started
aws
ใช้เมื่อนักพัฒนาต้องการสร้างโปรเจกต์เอเจนต์ใหม่หรือเริ่มต้นใช้งาน AgentCore จัดการเกี่ยวกับการเลือกเฟรมเวิร์ก การสร้างโครงโปรเจกต์ การดีพลอยครั้งแรก และ…
official
agents-harden
aws
Use when preparing your agent for production — IAM scoping, inbound auth (JWT, SigV4), secrets management, cold start optimization, session lifecycle, rate…
official
agents-pay
aws
Use when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying…
official
amazon-aurora-mysql
aws
Amazon Aurora MySQL — creates, modifies, and advises on Aurora MySQL clusters specifically (MySQL-compatible engine, Aurora serverless, parallel query).…
official