2021-06-18 11:45:39 +09:30
|
|
|
# aws secretsmanager
|
|
|
|
|
|
|
|
> Store, manage, and retrieve secrets.
|
|
|
|
> More information: <https://docs.aws.amazon.com/cli/latest/reference/secretsmanager/>.
|
|
|
|
|
|
|
|
- Show secrets stored by the secrets manager in the current account:
|
|
|
|
|
|
|
|
`aws secretsmanager list-secrets`
|
|
|
|
|
2024-11-13 07:48:14 +11:00
|
|
|
- List all secrets but only show the secret names and ARNs (easy to view):
|
|
|
|
|
|
|
|
`aws secretsmanager list-secrets --query 'SecretList[*].{Name: Name, ARN: ARN}'`
|
|
|
|
|
2021-06-18 11:45:39 +09:30
|
|
|
- Create a secret:
|
|
|
|
|
2024-11-13 07:48:14 +11:00
|
|
|
`aws secretsmanager create-secret --name {{name}} --description "{{secret_description}}" --secret-string '{{secret}}'`
|
2021-06-18 11:45:39 +09:30
|
|
|
|
2024-11-13 07:48:14 +11:00
|
|
|
- Delete a secret (append `--force-delete-without-recovery` to delete immediately without any recovery period):
|
2021-06-18 11:45:39 +09:30
|
|
|
|
2024-11-13 07:48:14 +11:00
|
|
|
`aws secretsmanager delete-secret --secret-id {{name|arn}}`
|
2021-06-18 11:45:39 +09:30
|
|
|
|
|
|
|
- View details of a secret except for secret text:
|
|
|
|
|
2024-11-13 07:48:14 +11:00
|
|
|
`aws secretsmanager describe-secret --secret-id {{name|arn}}`
|
2021-06-18 11:45:39 +09:30
|
|
|
|
|
|
|
- Retrieve the value of a secret (to get the latest version of the secret omit `--version-stage`):
|
|
|
|
|
2024-11-13 07:48:14 +11:00
|
|
|
`aws secretsmanager get-secret-value --secret-id {{name|arn}} --version-stage {{version_of_secret}}`
|
2021-06-18 11:45:39 +09:30
|
|
|
|
|
|
|
- Rotate the secret immediately using a Lambda function:
|
|
|
|
|
2024-11-13 07:48:14 +11:00
|
|
|
`aws secretsmanager rotate-secret --secret-id {{name|arn}} --rotation-lambda-arn {{arn_of_lambda_function}}`
|
2021-06-18 11:45:39 +09:30
|
|
|
|
|
|
|
- Rotate the secret automatically every 30 days using a Lambda function:
|
|
|
|
|
2024-11-13 07:48:14 +11:00
|
|
|
`aws secretsmanager rotate-secret --secret-id {{name|arn}} --rotation-lambda-arn {{arn_of_lambda_function}} --rotation-rules AutomaticallyAfterDays={{30}}`
|