diff --git a/backend/src/services/secret-sync/aws-parameter-store/aws-parameter-store-sync-fns.ts b/backend/src/services/secret-sync/aws-parameter-store/aws-parameter-store-sync-fns.ts index 9fa25ba76..9ca035774 100644 --- a/backend/src/services/secret-sync/aws-parameter-store/aws-parameter-store-sync-fns.ts +++ b/backend/src/services/secret-sync/aws-parameter-store/aws-parameter-store-sync-fns.ts @@ -317,11 +317,13 @@ export const AwsParameterStoreSyncFns = { continue; } + const keyId = syncOptions.keyId ?? "alias/aws/ssm"; + // create parameter or update if changed if ( !(key in awsParameterStoreSecretsRecord) || value !== awsParameterStoreSecretsRecord[key].Value || - (syncOptions.keyId ?? "alias/aws/ssm") !== awsParameterStoreMetadataRecord[key]?.KeyId + keyId !== awsParameterStoreMetadataRecord[key]?.KeyId ) { try { await putParameter(ssm, { @@ -329,7 +331,7 @@ export const AwsParameterStoreSyncFns = { Type: "SecureString", Value: value, Overwrite: true, - KeyId: syncOptions.keyId + KeyId: keyId }); } catch (error) { throw new SecretSyncError({ diff --git a/backend/src/services/secret-sync/aws-secrets-manager/aws-secrets-manager-sync-fns.ts b/backend/src/services/secret-sync/aws-secrets-manager/aws-secrets-manager-sync-fns.ts index c374a209c..d4f272475 100644 --- a/backend/src/services/secret-sync/aws-secrets-manager/aws-secrets-manager-sync-fns.ts +++ b/backend/src/services/secret-sync/aws-secrets-manager/aws-secrets-manager-sync-fns.ts @@ -318,6 +318,8 @@ export const AwsSecretsManagerSyncFns = { const syncTagsRecord = Object.fromEntries(syncOptions.tags?.map((tag) => [tag.key, tag.value]) ?? []); + const keyId = syncOptions.keyId ?? "alias/aws/secretsmanager"; + if (destinationConfig.mappingBehavior === AwsSecretsManagerSyncMappingBehavior.OneToOne) { for await (const entry of Object.entries(secretMap)) { const [key, { value, secretMetadata }] = entry; @@ -330,15 +332,12 @@ export const AwsSecretsManagerSyncFns = { if (awsSecretsRecord[key]) { // skip secrets that haven't changed - if ( - awsValuesRecord[key]?.SecretString !== value || - (syncOptions.keyId ?? "alias/aws/secretsmanager") !== awsDescriptionsRecord[key]?.KmsKeyId - ) { + if (awsValuesRecord[key]?.SecretString !== value || keyId !== awsDescriptionsRecord[key]?.KmsKeyId) { try { await updateSecret(client, { SecretId: key, SecretString: value, - KmsKeyId: syncOptions.keyId + KmsKeyId: keyId }); } catch (error) { throw new SecretSyncError({ @@ -352,7 +351,7 @@ export const AwsSecretsManagerSyncFns = { await createSecret(client, { Name: key, SecretString: value, - KmsKeyId: syncOptions.keyId + KmsKeyId: keyId }); } catch (error) { throw new SecretSyncError({ @@ -416,17 +415,17 @@ export const AwsSecretsManagerSyncFns = { Object.fromEntries(Object.entries(secretMap).map(([key, secretData]) => [key, secretData.value])) ); - if (awsValuesRecord[destinationConfig.secretName]) { + if (awsSecretsRecord[destinationConfig.secretName]) { await updateSecret(client, { SecretId: destinationConfig.secretName, SecretString: secretValue, - KmsKeyId: syncOptions.keyId + KmsKeyId: keyId }); } else { await createSecret(client, { Name: destinationConfig.secretName, SecretString: secretValue, - KmsKeyId: syncOptions.keyId + KmsKeyId: keyId }); } @@ -458,22 +457,6 @@ export const AwsSecretsManagerSyncFns = { }); } } - - for await (const secretKey of Object.keys(awsSecretsRecord)) { - if (secretKey === destinationConfig.secretName) { - // eslint-disable-next-line no-continue - continue; - } - - try { - await deleteSecret(client, secretKey); - } catch (error) { - throw new SecretSyncError({ - error, - secretKey - }); - } - } } }, getSecrets: async (secretSync: TAwsSecretsManagerSyncWithCredentials): Promise => { diff --git a/docs/images/app-connections/aws/kms-key-user.png b/docs/images/app-connections/aws/kms-key-user.png new file mode 100644 index 000000000..c94edea67 Binary files /dev/null and b/docs/images/app-connections/aws/kms-key-user.png differ diff --git a/docs/images/app-connections/aws/parameter-store-permissions.png b/docs/images/app-connections/aws/parameter-store-permissions.png index 1fb2b8118..0c5191e37 100644 Binary files a/docs/images/app-connections/aws/parameter-store-permissions.png and b/docs/images/app-connections/aws/parameter-store-permissions.png differ diff --git a/docs/images/app-connections/aws/secrets-manager-permissions.png b/docs/images/app-connections/aws/secrets-manager-permissions.png index 57d2eb2e2..6c60d9b83 100644 Binary files a/docs/images/app-connections/aws/secrets-manager-permissions.png and b/docs/images/app-connections/aws/secrets-manager-permissions.png differ diff --git a/docs/integrations/app-connections/aws.mdx b/docs/integrations/app-connections/aws.mdx index f7339d80c..30181213f 100644 --- a/docs/integrations/app-connections/aws.mdx +++ b/docs/integrations/app-connections/aws.mdx @@ -82,22 +82,26 @@ Infisical supports two methods for connecting to AWS. "Sid": "AllowSecretsManagerAccess", "Effect": "Allow", "Action": [ - "secretsmanager:GetSecretValue", - "secretsmanager:CreateSecret", - "secretsmanager:UpdateSecret", - "secretsmanager:DescribeSecret", - "secretsmanager:TagResource", - "secretsmanager:UntagResource", - "kms:ListKeys", // if you need to specify the KMS key - "kms:ListAliases", // if you need to specify the KMS key - "kms:Encrypt", // if you need to specify the KMS key - "kms:Decrypt" // if you need to specify the KMS key + "secretsmanager:ListSecrets", + "secretsmanager:GetSecretValue", + "secretsmanager:BatchGetSecretValue", + "secretsmanager:CreateSecret", + "secretsmanager:UpdateSecret", + "secretsmanager:DeleteSecret", + "secretsmanager:DescribeSecret", + "secretsmanager:TagResource", + "secretsmanager:UntagResource", + "kms:ListAliases", // if you need to specify the KMS key + "kms:Encrypt", // if you need to specify the KMS key + "kms:Decrypt", // if you need to specify the KMS key + "kms:DescribeKey" // if you need to specify the KMS key ], "Resource": "*" } ] } ``` + If using a custom KMS key, be sure to add the IAM role as a key user. ![KMS Key IAM Role User](/images/app-connections/aws/kms-key-user.png) Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store: @@ -112,25 +116,25 @@ Infisical supports two methods for connecting to AWS. "Sid": "AllowSSMAccess", "Effect": "Allow", "Action": [ - "ssm:PutParameter", - "ssm:DeleteParameter", - "ssm:GetParameters", - "ssm:GetParametersByPath", - "ssm:DescribeParameters", - "ssm:DeleteParameters", - "ssm:ListTagsForResource", // if you need to add tags to secrets - "ssm:AddTagsToResource", // if you need to add tags to secrets - "ssm:RemoveTagsFromResource", // if you need to add tags to secrets - "kms:ListKeys", // if you need to specify the KMS key - "kms:ListAliases", // if you need to specify the KMS key - "kms:Encrypt", // if you need to specify the KMS key - "kms:Decrypt" // if you need to specify the KMS key + "ssm:PutParameter", + "ssm:GetParameters", + "ssm:GetParametersByPath", + "ssm:DescribeParameters", + "ssm:DeleteParameters", + "ssm:ListTagsForResource", // if you need to add tags to secrets + "ssm:AddTagsToResource", // if you need to add tags to secrets + "ssm:RemoveTagsFromResource", // if you need to add tags to secrets + "kms:ListAliases", // if you need to specify the KMS key + "kms:Encrypt", // if you need to specify the KMS key + "kms:Decrypt", // if you need to specify the KMS key + "kms:DescribeKey" // if you need to specify the KMS key ], "Resource": "*" } ] } ``` + If using a custom KMS key, be sure to add the IAM role as a key user. ![KMS Key IAM Role User](/images/app-connections/aws/kms-key-user.png) @@ -225,22 +229,26 @@ Infisical supports two methods for connecting to AWS. "Sid": "AllowSecretsManagerAccess", "Effect": "Allow", "Action": [ - "secretsmanager:GetSecretValue", - "secretsmanager:CreateSecret", - "secretsmanager:UpdateSecret", - "secretsmanager:DescribeSecret", - "secretsmanager:TagResource", - "secretsmanager:UntagResource", - "kms:ListKeys", // if you need to specify the KMS key - "kms:ListAliases", // if you need to specify the KMS key - "kms:Encrypt", // if you need to specify the KMS key - "kms:Decrypt" // if you need to specify the KMS key + "secretsmanager:ListSecrets", + "secretsmanager:GetSecretValue", + "secretsmanager:BatchGetSecretValue", + "secretsmanager:CreateSecret", + "secretsmanager:UpdateSecret", + "secretsmanager:DeleteSecret", + "secretsmanager:DescribeSecret", + "secretsmanager:TagResource", + "secretsmanager:UntagResource", + "kms:ListAliases", // if you need to specify the KMS key + "kms:Encrypt", // if you need to specify the KMS key + "kms:Decrypt", // if you need to specify the KMS key + "kms:DescribeKey" // if you need to specify the KMS key ], "Resource": "*" } ] } ``` + If using a custom KMS key, be sure to add the IAM role as a key user. ![KMS Key IAM Role User](/images/app-connections/aws/kms-key-user.png) Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store: @@ -255,25 +263,25 @@ Infisical supports two methods for connecting to AWS. "Sid": "AllowSSMAccess", "Effect": "Allow", "Action": [ - "ssm:PutParameter", - "ssm:DeleteParameter", - "ssm:GetParameters", - "ssm:GetParametersByPath", - "ssm:DescribeParameters", - "ssm:DeleteParameters", - "ssm:ListTagsForResource", // if you need to add tags to secrets - "ssm:AddTagsToResource", // if you need to add tags to secrets - "ssm:RemoveTagsFromResource", // if you need to add tags to secrets - "kms:ListKeys", // if you need to specify the KMS key - "kms:ListAliases", // if you need to specify the KMS key - "kms:Encrypt", // if you need to specify the KMS key - "kms:Decrypt" // if you need to specify the KMS key + "ssm:PutParameter", + "ssm:GetParameters", + "ssm:GetParametersByPath", + "ssm:DescribeParameters", + "ssm:DeleteParameters", + "ssm:ListTagsForResource", // if you need to add tags to secrets + "ssm:AddTagsToResource", // if you need to add tags to secrets + "ssm:RemoveTagsFromResource", // if you need to add tags to secrets + "kms:ListAliases", // if you need to specify the KMS key + "kms:Encrypt", // if you need to specify the KMS key + "kms:Decrypt", // if you need to specify the KMS key + "kms:DescribeKey" // if you need to specify the KMS key ], "Resource": "*" } ] } ``` + If using a custom KMS key, be sure to add the IAM role as a key user. ![KMS Key IAM Role User](/images/app-connections/aws/kms-key-user.png) diff --git a/docs/integrations/secret-syncs/overview.mdx b/docs/integrations/secret-syncs/overview.mdx index 7b92a55e3..bbe333efc 100644 --- a/docs/integrations/secret-syncs/overview.mdx +++ b/docs/integrations/secret-syncs/overview.mdx @@ -80,7 +80,7 @@ via the UI or API for the third-party service you intend to sync secrets to. Secret Syncs are the source of truth for connected third-party services. Any secret, including associated data, not present or imported in Infisical before syncing will be - overwritten, and changes directly in the connected service outside of infisical may also + overwritten, and changes made directly in the connected service outside of infisical may also be overwritten by future syncs. diff --git a/frontend/src/components/secret-syncs/forms/CreateSecretSyncForm.tsx b/frontend/src/components/secret-syncs/forms/CreateSecretSyncForm.tsx index 8a9816312..dab582f8a 100644 --- a/frontend/src/components/secret-syncs/forms/CreateSecretSyncForm.tsx +++ b/frontend/src/components/secret-syncs/forms/CreateSecretSyncForm.tsx @@ -138,8 +138,8 @@ export const CreateSecretSyncForm = ({ destination, onComplete, onCancel }: Prop

Secret Syncs are the source of truth for connected third-party services. Any secret, including associated data, not present or imported in Infisical before syncing will be - overwritten, and changes directly in the connected service outside of infisical may also - be overwritten by future syncs. + overwritten, and changes made directly in the connected service outside of infisical may + also be overwritten by future syncs.

diff --git a/frontend/src/components/secret-syncs/forms/SecretSyncOptionsFields/AwsParameterStoreSyncOptionsFields.tsx b/frontend/src/components/secret-syncs/forms/SecretSyncOptionsFields/AwsParameterStoreSyncOptionsFields.tsx index c35f4d31a..4b1467182 100644 --- a/frontend/src/components/secret-syncs/forms/SecretSyncOptionsFields/AwsParameterStoreSyncOptionsFields.tsx +++ b/frontend/src/components/secret-syncs/forms/SecretSyncOptionsFields/AwsParameterStoreSyncOptionsFields.tsx @@ -70,11 +70,11 @@ export const AwsParameterStoreSyncOptionsFields = () => { To configure a KMS key, ensure the following permissions are present on the selected IAM role:{" "} - "kms:ListKeys" + "kms:ListAliases" ,{" "} - "kms:ListAliases" + "kms:DescribeKey" ,{" "} diff --git a/frontend/src/components/secret-syncs/forms/SecretSyncOptionsFields/AwsSecretsManagerSyncOptionsFields.tsx b/frontend/src/components/secret-syncs/forms/SecretSyncOptionsFields/AwsSecretsManagerSyncOptionsFields.tsx index 87e983d6c..5e4768dda 100644 --- a/frontend/src/components/secret-syncs/forms/SecretSyncOptionsFields/AwsSecretsManagerSyncOptionsFields.tsx +++ b/frontend/src/components/secret-syncs/forms/SecretSyncOptionsFields/AwsSecretsManagerSyncOptionsFields.tsx @@ -72,11 +72,11 @@ export const AwsSecretsManagerSyncOptionsFields = () => { To configure a KMS key, ensure the following permissions are present on the selected IAM role:{" "} - "kms:ListKeys" + "kms:ListAliases" ,{" "} - "kms:ListAliases" + "kms:DescribeKey" ,{" "}