|
|
|
|
@@ -6,14 +6,41 @@ description: "Learn how to automatically rotate Access Key Id and Secret Key of
|
|
|
|
|
Infisical's AWS IAM User secret rotation capability lets you update the **Access key** and **Secret access key** credentials of a target IAM user from within Infisical
|
|
|
|
|
at a specified interval or on-demand.
|
|
|
|
|
|
|
|
|
|
## Prerequisites
|
|
|
|
|
|
|
|
|
|
- Create an [AWS Connection](/integrations/app-connections/aws) with the required **Secret Rotation** audience and permissions
|
|
|
|
|
- Add the following permissions to your IAM Role/IAM User Permission policy set used by your AWS Connection:
|
|
|
|
|
|
|
|
|
|
```json
|
|
|
|
|
{
|
|
|
|
|
"Version": "2012-10-17",
|
|
|
|
|
"Statement": [
|
|
|
|
|
{
|
|
|
|
|
"Effect": "Allow",
|
|
|
|
|
"Action": [
|
|
|
|
|
"iam:ListAccessKeys",
|
|
|
|
|
"iam:CreateAccessKey",
|
|
|
|
|
"iam:UpdateAccessKey",
|
|
|
|
|
"iam:DeleteAccessKey"
|
|
|
|
|
],
|
|
|
|
|
"Resource": "*"
|
|
|
|
|
},
|
|
|
|
|
{
|
|
|
|
|
"Effect": "Allow",
|
|
|
|
|
"Action": "iam:ListUsers",
|
|
|
|
|
"Resource": "*"
|
|
|
|
|
}
|
|
|
|
|
]
|
|
|
|
|
}
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
## Workflow
|
|
|
|
|
|
|
|
|
|
The typical workflow for using the AWS IAM User rotation strategy consists of four steps:
|
|
|
|
|
|
|
|
|
|
1. Creating the target IAM user whose credentials you wish to rotate.
|
|
|
|
|
2. Creating the managing IAM user used by Infisical to rotate the credentials of the target IAM user.
|
|
|
|
|
3. Configuring the rotation strategy in Infisical with the credentials of the managing IAM user.
|
|
|
|
|
4. Pressing the **Rotate** button in the Infisical dashboard to trigger the rotation of the target IAM user's credentials. The strategy can also be configured to rotate the credentials automatically at a specified interval.
|
|
|
|
|
2. Configuring the rotation strategy in Infisical with the credentials of the managing IAM user.
|
|
|
|
|
3. Pressing the **Rotate** button in the Infisical dashboard to trigger the rotation of the target IAM user's credentials. The strategy can also be configured to rotate the credentials automatically at a specified interval.
|
|
|
|
|
|
|
|
|
|
In the following steps, we explore the end-to-end workflow for setting up this strategy in Infisical.
|
|
|
|
|
|
|
|
|
|
@@ -22,122 +49,152 @@ In the following steps, we explore the end-to-end workflow for setting up this s
|
|
|
|
|
To begin, create an IAM user whose credentials you wish to rotate. If you already have an IAM user,
|
|
|
|
|
then you can skip this step.
|
|
|
|
|
</Step>
|
|
|
|
|
<Step title="Create the managing IAM user">
|
|
|
|
|
Next, create another IAM user to be used by Infisical to rotate the credentials of the IAM user in the previous step.
|
|
|
|
|
|
|
|
|
|
2.1. In your AWS console, head to IAM > Access management > Users and press **Create user**.
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
2.2. Next, give the user a username like **infisical-rotation-manager** and press **Next**.
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
2.3. Next, in the **Set permissions** step, select **Attach policies directly** and then press **Create policy**.
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
2.4. Next, in the **Policy editor**, paste the following JSON and press **Next**:
|
|
|
|
|
|
|
|
|
|
```json
|
|
|
|
|
{
|
|
|
|
|
"Version": "2012-10-17",
|
|
|
|
|
"Statement": [
|
|
|
|
|
{
|
|
|
|
|
"Sid": "VisualEditor0",
|
|
|
|
|
"Effect": "Allow",
|
|
|
|
|
"Action": [
|
|
|
|
|
"iam:DeleteAccessKey",
|
|
|
|
|
"iam:GetAccessKeyLastUsed",
|
|
|
|
|
"iam:CreateAccessKey"
|
|
|
|
|
],
|
|
|
|
|
"Resource": "*"
|
|
|
|
|
}
|
|
|
|
|
]
|
|
|
|
|
}
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
<Note>
|
|
|
|
|
The IAM policy above uses the wildcard option in Resource: "*".
|
|
|
|
|
|
|
|
|
|
You may want to restrict the policy to a specific path, and make any adjustments as necessary, to control access for the managing user in production.
|
|
|
|
|
|
|
|
|
|
Read more about this [here](https://aws.amazon.com/blogs/security/optimize-aws-administration-with-iam-paths/).
|
|
|
|
|
</Note>
|
|
|
|
|
|
|
|
|
|
In the **Review and create** step, give the policy a name like **infisical-rotation-manager**, press **Create policy** to finish creating the policy.
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
2.5. Back in the **Set permissions** step from step 2.3, refresh the policy list and search for the policy you just created from step 2.4.
|
|
|
|
|
|
|
|
|
|
Select the policy and press **Next**.
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
In the **Review and create** step, press **Create user** to finish creating the IAM user.
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
2.5. Having created the user, head to its Security credentials > Access keys and press **Create access key**.
|
|
|
|
|
|
|
|
|
|
Follow the subsequent steps to create the **access key** and **secret access key** credential pair for the user.
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
At the end of the flow, copy the **Access key** and **Secret access key** to use when configuring the AWS IAM User rotation strategy back in Infisical next.
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
</Step>
|
|
|
|
|
<Step title="Configure the AWS IAM User secret rotation strategy in Infisical">
|
|
|
|
|
3.1. Back in Infisical, head to the Project > Secrets > Environment and path where you want the rotated AWS IAM credentials to appear and create two placeholder secrets.
|
|
|
|
|
|
|
|
|
|
In this example, we'll create two secrets called `AWS_ACCESS_KEY` and `AWS_SECRET_ACCESS_KEY`.
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
3.2. Next, in the **Secret Rotation** tab, press on the **AWS IAM** tile to configure the AWS IAM User rotation strategy.
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
3.3. Input the configuration details for the AWS IAM User rotation strategy obtained from steps 1 and 2:
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
Here's some guidance on each field:
|
|
|
|
|
|
|
|
|
|
- Manager User Access Key: The managing IAM user's access key from step 2.5.
|
|
|
|
|
- Manager User Secret Key: The managing IAM user's secret access key from step 2.5.
|
|
|
|
|
- Manager User AWS Region: The [AWS region](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Concepts.RegionsAndAvailabilityZones.html) for Infisical to make requests to such as `us-east-1`.
|
|
|
|
|
- IAM Username: The IAM username of the user from step 1.
|
|
|
|
|
|
|
|
|
|
Next, specify the output secret mappings configuration for the rotated AWS IAM credentials; this is the secrets whose values will be replaced with new credentials after each rotation.
|
|
|
|
|
Here, you can also specify a rotation interval for the credentials to be automatically rotated periodically.
|
|
|
|
|
<Tabs>
|
|
|
|
|
<Tab title="Infisical UI">
|
|
|
|
|
1. Navigate to your Secret Manager Project's Dashboard and select **Add Secret Rotation** from the actions dropdown.
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
In this example, we want to map the output of the rotated AWS IAM credentials to the secrets that we created in step 3.1 (i.e. `AWS_ACCESS_KEY` and `AWS_SECRET_ACCESS_KEY`).
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
Finally, press **Submit** to create the secret rotation strategy.
|
|
|
|
|
</Step>
|
|
|
|
|
<Step title="Rotate secrets in Infisical">
|
|
|
|
|
You should now see the AWS IAM User rotation strategy listed in the **Secret Rotation** tab.
|
|
|
|
|
|
|
|
|
|
To manually trigger a rotation, you can press the **Rotate** button on the strategy.
|
|
|
|
|
Once triggered, the secrets in step 3.1 should be updated with new rotated credential values.
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
2. Select the **AWS IAM User Secret** option.
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
3. Select the **AWS Connection** to use and configure the rotation behavior. Then click **Next**.
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
- **AWS Connection** - the connection that will perform the rotation of the specified application's Client Secret.
|
|
|
|
|
- **Rotation Interval** - the interval, in days, that once elapsed will trigger a rotation.
|
|
|
|
|
- **Rotate At** - the local time of day when rotation should occur once the interval has elapsed.
|
|
|
|
|
- **Auto-Rotation Enabled** - whether secrets should automatically be rotated once the rotation interval has elapsed. Disable this option to manually rotate secrets or pause secret rotation.
|
|
|
|
|
|
|
|
|
|
4. Select the AWS IAM user and the region of the user whose credentials you want to rotate. Then click **Next**.
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
5. Specify the secret names that the client credentials should be mapped to. Then click **Next**.
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
- **Client ID** - the name of the secret that the application Client ID will be mapped to.
|
|
|
|
|
- **Client Secret** - the name of the secret that the rotated Client Secret will be mapped to.
|
|
|
|
|
|
|
|
|
|
6. Give your rotation a name and description (optional). Then click **Next**.
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
- **Name** - the name of the secret rotation configuration. Must be slug-friendly.
|
|
|
|
|
- **Description** (optional) - a description of this rotation configuration.
|
|
|
|
|
|
|
|
|
|
7. Review your configuration, then click **Create Secret Rotation**.
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
8. Your **AWS IAM User** credentials are now available for use via the mapped secrets.
|
|
|
|
|

|
|
|
|
|
</Tab>
|
|
|
|
|
<Tab title="API">
|
|
|
|
|
To create an AWS IAM User Rotation, make an API request to the [Create AWS IAM User Rotation](/api-reference/endpoints/secret-rotations/aws-iam-user-secret/create) API endpoint.
|
|
|
|
|
|
|
|
|
|
You will first need the **User Name** of the AWS IAM user you want to rotate the secret for. This can be obtained from the IAM console, on Users tab.
|
|
|
|
|

|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
### Sample request
|
|
|
|
|
|
|
|
|
|
```bash Request
|
|
|
|
|
curl --request POST \
|
|
|
|
|
--url https://us.infisical.com/api/v2/secret-rotations/aws-iam-user-secret \
|
|
|
|
|
--header 'Content-Type: application/json' \
|
|
|
|
|
--data '{
|
|
|
|
|
"name": "<string>",
|
|
|
|
|
"projectId": "<string>",
|
|
|
|
|
"description": "<string>",
|
|
|
|
|
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
|
|
|
|
"environment": "<string>",
|
|
|
|
|
"secretPath": "<string>",
|
|
|
|
|
"isAutoRotationEnabled": true,
|
|
|
|
|
"rotationInterval": 2,
|
|
|
|
|
"rotateAtUtc": {
|
|
|
|
|
"hours": 11.5,
|
|
|
|
|
"minutes": 29.5
|
|
|
|
|
},
|
|
|
|
|
"parameters": {
|
|
|
|
|
"clientName": "<string>",
|
|
|
|
|
"region": "us-east-1"
|
|
|
|
|
},
|
|
|
|
|
"secretsMapping": {
|
|
|
|
|
"accessKeyId": "<string>",
|
|
|
|
|
"secretAccessKey": "<string>"
|
|
|
|
|
}
|
|
|
|
|
}'
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
### Sample response
|
|
|
|
|
|
|
|
|
|
```bash Response
|
|
|
|
|
{
|
|
|
|
|
"secretRotation": {
|
|
|
|
|
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
|
|
|
|
"name": "<string>",
|
|
|
|
|
"description": "<string>",
|
|
|
|
|
"secretsMapping": {
|
|
|
|
|
"accessKeyId": "<string>",
|
|
|
|
|
"secretAccessKey": "<string>"
|
|
|
|
|
},
|
|
|
|
|
"isAutoRotationEnabled": true,
|
|
|
|
|
"activeIndex": 0,
|
|
|
|
|
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
|
|
|
|
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
|
|
|
|
"createdAt": "2023-11-07T05:31:56Z",
|
|
|
|
|
"updatedAt": "2023-11-07T05:31:56Z",
|
|
|
|
|
"rotationInterval": 123,
|
|
|
|
|
"rotationStatus": "<string>",
|
|
|
|
|
"lastRotationAttemptedAt": "2023-11-07T05:31:56Z",
|
|
|
|
|
"lastRotatedAt": "2023-11-07T05:31:56Z",
|
|
|
|
|
"lastRotationJobId": "<string>",
|
|
|
|
|
"nextRotationAt": "2023-11-07T05:31:56Z",
|
|
|
|
|
"isLastRotationManual": true,
|
|
|
|
|
"connection": {
|
|
|
|
|
"app": "aws",
|
|
|
|
|
"name": "<string>",
|
|
|
|
|
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
|
|
|
|
},
|
|
|
|
|
"environment": {
|
|
|
|
|
"slug": "<string>",
|
|
|
|
|
"name": "<string>",
|
|
|
|
|
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
|
|
|
|
},
|
|
|
|
|
"projectId": "<string>",
|
|
|
|
|
"folder": {
|
|
|
|
|
"id": "<string>",
|
|
|
|
|
"path": "<string>"
|
|
|
|
|
},
|
|
|
|
|
"rotateAtUtc": {
|
|
|
|
|
"hours": 11.5,
|
|
|
|
|
"minutes": 29.5
|
|
|
|
|
},
|
|
|
|
|
"lastRotationMessage": "<string>",
|
|
|
|
|
"type": "aws-iam-user-secret",
|
|
|
|
|
"parameters": {
|
|
|
|
|
"clientName": "<string>",
|
|
|
|
|
"region": "us-east-1"
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
```
|
|
|
|
|
</Tab>
|
|
|
|
|
</Tabs>
|
|
|
|
|
</Step>
|
|
|
|
|
</Steps>
|
|
|
|
|
|
|
|
|
|
**FAQ**
|
|
|
|
|
|
|
|
|
|
<AccordionGroup>
|
|
|
|
|
<Accordion title="Why are my AWS IAM credentials not rotating?">
|
|
|
|
|
There are a few reasons for why this might happen:
|
|
|
|
|
|
|
|
|
|
- The strategy configuration is invalid (e.g. the managing IAM user's credentials are incorrect, the target IAM username is incorrect, etc.).
|
|
|
|
|
- The managing IAM user is insufficently permissioned to rotate the credentials of the target IAM user. For instance, you may have setup [paths](https://aws.amazon.com/blogs/security/optimize-aws-administration-with-iam-paths/) for the managing IAM user and the policy does not have the necessary permissions to rotate the credentials.
|
|
|
|
|
- The target IAM user already has 2 access keys configured in AWS; you should delete one of the access keys to allow for rotation.
|
|
|
|
|
</Accordion>
|
|
|
|
|
</AccordionGroup>
|
|
|
|
|
<Accordion title="Why are my AWS IAM credentials not rotating?">
|
|
|
|
|
There are a few reasons for why this might happen: - The strategy
|
|
|
|
|
configuration is invalid (e.g. the managing IAM user's credentials are
|
|
|
|
|
incorrect, the target AWS region is incorrect, etc.). - The managing IAM
|
|
|
|
|
user is insufficently permissioned to rotate the credentials of the target
|
|
|
|
|
IAM user. For instance, you may have setup
|
|
|
|
|
[paths](https://aws.amazon.com/blogs/security/optimize-aws-administration-with-iam-paths/)
|
|
|
|
|
for the managing IAM user and the policy does not have the necessary
|
|
|
|
|
permissions to rotate the credentials. - The target IAM user already has 2
|
|
|
|
|
access keys configured in AWS; you should delete one of the access keys to
|
|
|
|
|
allow for rotation.
|
|
|
|
|
</Accordion>
|
|
|
|
|
</AccordionGroup>
|
|
|
|
|
|