mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
508 lines
30 KiB
Plaintext
508 lines
30 KiB
Plaintext
---
|
||
title: "AWS Connection"
|
||
description: "Learn how to configure an AWS Connection for Infisical."
|
||
---
|
||
|
||
Infisical supports two methods for connecting to AWS.
|
||
|
||
<Tabs>
|
||
<Tab title="Assume Role (Recommended)">
|
||
Infisical will assume the provided role in your AWS account securely, without the need to share any credentials.
|
||
|
||
<Accordion title="Self-Hosted Instance">
|
||
To connect your self-hosted Infisical instance with AWS, you need to set up an AWS IAM User account that can assume the configured AWS IAM Role.
|
||
|
||
If your instance is deployed on AWS, the aws-sdk will automatically retrieve the credentials. Ensure that you assign the provided permission policy to your deployed instance, such as ECS or EC2.
|
||
|
||
The following steps are for instances not deployed on AWS:
|
||
<Steps>
|
||
<Step title="Create an IAM User">
|
||
Navigate to [Create IAM User](https://console.aws.amazon.com/iamv2/home#/users/create) in your AWS Console.
|
||
</Step>
|
||
<Step title="Create an Inline Policy">
|
||
Attach the following inline permission policy to the IAM User to allow it to assume any IAM Roles:
|
||
```json
|
||
{
|
||
"Version": "2012-10-17",
|
||
"Statement": [
|
||
{
|
||
"Sid": "AllowAssumeAnyRole",
|
||
"Effect": "Allow",
|
||
"Action": "sts:AssumeRole",
|
||
"Resource": "arn:aws:iam::*:role/*"
|
||
}
|
||
]
|
||
}
|
||
```
|
||
</Step>
|
||
<Step title="Obtain the IAM User Credentials">
|
||
Obtain the AWS access key ID and secret access key for your IAM User by navigating to **IAM > Users > [Your User] > Security credentials > Access keys**.
|
||
|
||

|
||

|
||

|
||
</Step>
|
||
<Step title="Set Up Connection Keys">
|
||
1. Set the access key as **INF_APP_CONNECTION_AWS_ACCESS_KEY_ID**.
|
||
2. Set the secret key as **INF_APP_CONNECTION_AWS_SECRET_ACCESS_KEY**.
|
||
</Step>
|
||
</Steps>
|
||
</Accordion>
|
||
|
||
<Steps>
|
||
<Step title="Create the Managing User IAM Role for Infisical">
|
||
1. Navigate to the [Create IAM Role](https://console.aws.amazon.com/iamv2/home#/roles/create?step=selectEntities) page in your AWS Console.
|
||

|
||
|
||
2. Select **AWS Account** as the **Trusted Entity Type**.
|
||
3. Select **Another AWS Account** and provide the appropriate Infisical AWS Account ID: use **381492033652** for the **US region**, and **345594589636** for the **EU region**. This restricts the role to be assumed only by Infisical. If self-hosting, provide your AWS account number instead.
|
||
<Note>
|
||
**For Dedicated Instances**: Your AWS account ID differs from the one provided above. Please reach out to Infisical support to obtain your AWS account ID.
|
||
</Note>
|
||
4. (Recommended) <strong>Enable "Require external ID"</strong> and input your **Organization ID** to strengthen security and mitigate the [confused deputy problem](https://docs.aws.amazon.com/IAM/latest/UserGuide/confused-deputy.html).
|
||
|
||
<Warning type="warning" title="Security Best Practice: Use External ID to Prevent Confused Deputy Attacks">
|
||
When configuring an IAM Role that Infisical will assume, it’s highly recommended to enable the **"Require external ID"** option and specify your **Organization ID**.
|
||
|
||
This precaution helps protect your AWS account against the [confused deputy problem](https://docs.aws.amazon.com/IAM/latest/UserGuide/confused-deputy.html), a potential security vulnerability where Infisical could be tricked into performing actions on your behalf by an unauthorized actor.
|
||
|
||
<strong>Always enable "Require external ID" and use your Organization ID when setting up the IAM Role.</strong>
|
||
</Warning>
|
||
</Step>
|
||
|
||
<Step title="Add Required Permissions to the IAM Role">
|
||
Navigate to your IAM role permissions and click **Create Inline Policy**.
|
||
|
||

|
||
|
||
Depending on your use case, add one or more of the following policies to your IAM Role:
|
||
|
||
<Tabs>
|
||
<Tab title="Secret Sync">
|
||
<AccordionGroup>
|
||
<Accordion title="AWS Secrets Manager">
|
||
Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Secrets Manager:
|
||
|
||

|
||
|
||
```json
|
||
{
|
||
"Version": "2012-10-17",
|
||
"Statement": [
|
||
{
|
||
"Sid": "AllowSecretsManagerAccess",
|
||
"Effect": "Allow",
|
||
"Action": [
|
||
"secretsmanager:ListSecrets",
|
||
"secretsmanager:GetSecretValue",
|
||
"secretsmanager:BatchGetSecretValue",
|
||
"secretsmanager:CreateSecret",
|
||
"secretsmanager:UpdateSecret",
|
||
"secretsmanager:DeleteSecret",
|
||
"secretsmanager:DescribeSecret",
|
||
"secretsmanager:TagResource",
|
||
"secretsmanager:UntagResource",
|
||
"kms:ListAliases", // if you need to specify the KMS key
|
||
"kms:Encrypt", // if you need to specify the KMS key
|
||
"kms:Decrypt", // if you need to specify the KMS key
|
||
"kms:DescribeKey" // if you need to specify the KMS key
|
||
],
|
||
"Resource": "*"
|
||
}
|
||
]
|
||
}
|
||
```
|
||
<Note>If using a custom KMS key, be sure to add the IAM user or role as a key user. </Note>
|
||
</Accordion>
|
||
<Accordion title="AWS Parameter Store">
|
||
Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store:
|
||
|
||

|
||
|
||
```json
|
||
{
|
||
"Version": "2012-10-17",
|
||
"Statement": [
|
||
{
|
||
"Sid": "AllowSSMAccess",
|
||
"Effect": "Allow",
|
||
"Action": [
|
||
"ssm:PutParameter",
|
||
"ssm:GetParameters",
|
||
"ssm:GetParametersByPath",
|
||
"ssm:DescribeParameters",
|
||
"ssm:DeleteParameters",
|
||
"ssm:ListTagsForResource", // if you need to add tags to secrets
|
||
"ssm:AddTagsToResource", // if you need to add tags to secrets
|
||
"ssm:RemoveTagsFromResource", // if you need to add tags to secrets
|
||
"kms:ListAliases", // if you need to specify the KMS key
|
||
"kms:Encrypt", // if you need to specify the KMS key
|
||
"kms:Decrypt", // if you need to specify the KMS key
|
||
"kms:DescribeKey" // if you need to specify the KMS key
|
||
],
|
||
"Resource": "*"
|
||
}
|
||
]
|
||
}
|
||
```
|
||
<Note>If using a custom KMS key, be sure to add the IAM user or role as a key user. </Note>
|
||
</Accordion>
|
||
</AccordionGroup>
|
||
</Tab>
|
||
<Tab title="Secret Rotation">
|
||
<AccordionGroup>
|
||
<Accordion title="AWS IAM">
|
||
Use the following custom policy to grant the minimum permissions required by Infisical to rotate secrets to AWS Access Keys:
|
||
|
||

|
||
|
||
```json
|
||
{
|
||
"Version": "2012-10-17",
|
||
"Statement": [
|
||
{
|
||
"Effect": "Allow",
|
||
"Action": [
|
||
"iam:ListAccessKeys",
|
||
"iam:CreateAccessKey",
|
||
"iam:UpdateAccessKey",
|
||
"iam:DeleteAccessKey",
|
||
"iam:ListUsers"
|
||
],
|
||
"Resource": "*"
|
||
}
|
||
]
|
||
}
|
||
```
|
||
</Accordion>
|
||
</AccordionGroup>
|
||
</Tab>
|
||
<Tab title="PKI Sync">
|
||
<AccordionGroup>
|
||
<Accordion title="AWS Certificate Manager">
|
||
Use the following custom policy to grant the minimum permissions required by Infisical to sync certificates to AWS Certificate Manager:
|
||
|
||
```json
|
||
{
|
||
"Version": "2012-10-17",
|
||
"Statement": [
|
||
{
|
||
"Sid": "AllowCertificateManagerAccess",
|
||
"Effect": "Allow",
|
||
"Action": [
|
||
"acm:ListCertificates",
|
||
"acm:DescribeCertificate",
|
||
"acm:GetCertificate",
|
||
"acm:ImportCertificate",
|
||
"acm:ExportCertificate",
|
||
"acm:DeleteCertificate",
|
||
"acm:AddTagsToCertificate",
|
||
"acm:RemoveTagsFromCertificate",
|
||
"acm:ListTagsForCertificate"
|
||
],
|
||
"Resource": "*"
|
||
}
|
||
]
|
||
}
|
||
```
|
||
<Note>
|
||
- **ListCertificates**: Lists all certificates in the account
|
||
- **ImportCertificate**: Imports certificates from Infisical into AWS Certificate Manager
|
||
- **ExportCertificate**: Exports certificates for synchronization
|
||
- **DeleteCertificate**: Removes certificates that are no longer managed by Infisical
|
||
- **DescribeCertificate** and **GetCertificate**: Retrieves certificate details for comparison during sync
|
||
- Tag-related permissions: Manages certificate tags for identification and organization
|
||
</Note>
|
||
</Accordion>
|
||
</AccordionGroup>
|
||
</Tab>
|
||
</Tabs>
|
||
</Step>
|
||
|
||
<Step title="Copy the AWS IAM Role ARN">
|
||

|
||
</Step>
|
||
|
||
<Step title="Setup AWS Connection in Infisical">
|
||
<Tabs>
|
||
<Tab title="Infisical UI">
|
||
1. Navigate to the **App Connections** page in the desired project.
|
||

|
||
|
||
2. Select the **AWS Connection** option.
|
||

|
||
|
||
3. Select the **Assume Role** method option and provide the **AWS IAM Role ARN** obtained from the previous step and press **Connect to AWS**.
|
||

|
||
|
||
4. Your **AWS Connection** is now available for use.
|
||

|
||
</Tab>
|
||
<Tab title="API">
|
||
To create an AWS Connection, make an API request to the [Create AWS
|
||
Connection](/api-reference/endpoints/app-connections/aws/create) API endpoint.
|
||
|
||
### Sample request
|
||
|
||
```bash Request
|
||
curl --request POST \
|
||
--url https://app.infisical.com/api/v1/app-connections/aws \
|
||
--header 'Content-Type: application/json' \
|
||
--data '{
|
||
"name": "my-aws-connection",
|
||
"method": "assume-role",
|
||
"projectId": "7ffbb072-2575-495a-b5b0-127f88caef78",
|
||
"credentials": {
|
||
"roleArn": "...",
|
||
}
|
||
}'
|
||
```
|
||
|
||
### Sample response
|
||
|
||
```bash Response
|
||
{
|
||
"appConnection": {
|
||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||
"name": "my-aws-connection",
|
||
"projectId": "7ffbb072-2575-495a-b5b0-127f88caef78",
|
||
"version": 123,
|
||
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||
"createdAt": "2023-11-07T05:31:56Z",
|
||
"updatedAt": "2023-11-07T05:31:56Z",
|
||
"app": "aws",
|
||
"method": "assume-role",
|
||
"credentials": {}
|
||
}
|
||
}
|
||
```
|
||
</Tab>
|
||
</Tabs>
|
||
</Step>
|
||
</Steps>
|
||
|
||
</Tab>
|
||
<Tab title="Access Key">
|
||
Infisical will use the provided **Access Key ID** and **Secret Key** to connect to your AWS instance.
|
||
|
||
<Steps>
|
||
<Step title="Add Required Permissions to the IAM User">
|
||
Navigate to your IAM user permissions and click **Create Inline Policy**.
|
||
|
||

|
||
|
||
Depending on your use case, add one or more of the following policies to your user:
|
||
|
||
<Tabs>
|
||
<Tab title="Secret Sync">
|
||
<AccordionGroup>
|
||
<Accordion title="AWS Secrets Manager">
|
||
Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Secrets Manager:
|
||
|
||

|
||
|
||
```json
|
||
{
|
||
"Version": "2012-10-17",
|
||
"Statement": [
|
||
{
|
||
"Sid": "AllowSecretsManagerAccess",
|
||
"Effect": "Allow",
|
||
"Action": [
|
||
"secretsmanager:ListSecrets",
|
||
"secretsmanager:GetSecretValue",
|
||
"secretsmanager:BatchGetSecretValue",
|
||
"secretsmanager:CreateSecret",
|
||
"secretsmanager:UpdateSecret",
|
||
"secretsmanager:DeleteSecret",
|
||
"secretsmanager:DescribeSecret",
|
||
"secretsmanager:TagResource",
|
||
"secretsmanager:UntagResource",
|
||
"kms:ListAliases", // if you need to specify the KMS key
|
||
"kms:Encrypt", // if you need to specify the KMS key
|
||
"kms:Decrypt", // if you need to specify the KMS key
|
||
"kms:DescribeKey" // if you need to specify the KMS key
|
||
],
|
||
"Resource": "*"
|
||
}
|
||
]
|
||
}
|
||
```
|
||
<Note>If using a custom KMS key, be sure to add the IAM user or role as a key user. </Note>
|
||
</Accordion>
|
||
<Accordion title="AWS Parameter Store">
|
||
Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store:
|
||
|
||

|
||
|
||
```json
|
||
{
|
||
"Version": "2012-10-17",
|
||
"Statement": [
|
||
{
|
||
"Sid": "AllowSSMAccess",
|
||
"Effect": "Allow",
|
||
"Action": [
|
||
"ssm:PutParameter",
|
||
"ssm:GetParameters",
|
||
"ssm:GetParametersByPath",
|
||
"ssm:DescribeParameters",
|
||
"ssm:DeleteParameters",
|
||
"ssm:ListTagsForResource", // if you need to add tags to secrets
|
||
"ssm:AddTagsToResource", // if you need to add tags to secrets
|
||
"ssm:RemoveTagsFromResource", // if you need to add tags to secrets
|
||
"kms:ListAliases", // if you need to specify the KMS key
|
||
"kms:Encrypt", // if you need to specify the KMS key
|
||
"kms:Decrypt", // if you need to specify the KMS key
|
||
"kms:DescribeKey" // if you need to specify the KMS key
|
||
],
|
||
"Resource": "*"
|
||
}
|
||
]
|
||
}
|
||
```
|
||
<Note>If using a custom KMS key, be sure to add the IAM user or role as a key user. </Note>
|
||
</Accordion>
|
||
</AccordionGroup>
|
||
</Tab>
|
||
<Tab title="Secret Rotation">
|
||
<AccordionGroup>
|
||
<Accordion title="AWS IAM">
|
||
Use the following custom policy to grant the minimum permissions required by Infisical to rotate secrets to AWS Access Keys:
|
||
|
||

|
||
|
||
```json
|
||
{
|
||
"Version": "2012-10-17",
|
||
"Statement": [
|
||
{
|
||
"Effect": "Allow",
|
||
"Action": [
|
||
"iam:ListAccessKeys",
|
||
"iam:CreateAccessKey",
|
||
"iam:UpdateAccessKey",
|
||
"iam:DeleteAccessKey",
|
||
"iam:ListUsers"
|
||
],
|
||
"Resource": "*"
|
||
}
|
||
]
|
||
}
|
||
```
|
||
</Accordion>
|
||
</AccordionGroup>
|
||
</Tab>
|
||
<Tab title="PKI Sync">
|
||
<AccordionGroup>
|
||
<Accordion title="AWS Certificate Manager">
|
||
Use the following custom policy to grant the minimum permissions required by Infisical to sync certificates to AWS Certificate Manager:
|
||
|
||
```json
|
||
{
|
||
"Version": "2012-10-17",
|
||
"Statement": [
|
||
{
|
||
"Sid": "AllowCertificateManagerAccess",
|
||
"Effect": "Allow",
|
||
"Action": [
|
||
"acm:ListCertificates",
|
||
"acm:DescribeCertificate",
|
||
"acm:GetCertificate",
|
||
"acm:ImportCertificate",
|
||
"acm:ExportCertificate",
|
||
"acm:DeleteCertificate",
|
||
"acm:AddTagsToCertificate",
|
||
"acm:RemoveTagsFromCertificate",
|
||
"acm:ListTagsForCertificate"
|
||
],
|
||
"Resource": "*"
|
||
}
|
||
]
|
||
}
|
||
```
|
||
<Note>
|
||
- **ListCertificates**: Lists all certificates in the account
|
||
- **ImportCertificate**: Imports certificates from Infisical into AWS Certificate Manager
|
||
- **ExportCertificate**: Exports certificates for synchronization
|
||
- **DeleteCertificate**: Removes certificates that are no longer managed by Infisical
|
||
- **DescribeCertificate** and **GetCertificate**: Retrieves certificate details for comparison during sync
|
||
- Tag-related permissions: Manages certificate tags for identification and organization
|
||
</Note>
|
||
</Accordion>
|
||
</AccordionGroup>
|
||
</Tab>
|
||
</Tabs>
|
||
</Step>
|
||
<Step title="Obtain Access Key ID and Secret Access Key">
|
||
Retrieve an AWS **Access Key ID** and a **Secret Key** for your IAM user in **IAM > Users > User > Security credentials > Access keys**.
|
||
|
||

|
||

|
||

|
||
</Step>
|
||
<Step title="Setup AWS Connection in Infisical">
|
||
<Tabs>
|
||
<Tab title="Infisical UI">
|
||
1. Navigate to the **App Connections** page in the desired project.
|
||

|
||
|
||
2. Select the **AWS Connection** option.
|
||

|
||
|
||
3. Select the **Access Key** method option and provide the **Access Key ID** and **Secret Key** obtained from the previous step and press **Connect to AWS**.
|
||

|
||
|
||
4. Your **AWS Connection** is now available for use.
|
||

|
||
</Tab>
|
||
<Tab title="API">
|
||
To create an AWS Connection, make an API request to the [Create AWS
|
||
Connection](/api-reference/endpoints/app-connections/aws/create) API endpoint.
|
||
|
||
### Sample request
|
||
|
||
```bash Request
|
||
curl --request POST \
|
||
--url https://app.infisical.com/api/v1/app-connections/aws \
|
||
--header 'Content-Type: application/json' \
|
||
--data '{
|
||
"name": "my-aws-connection",
|
||
"method": "access-key",
|
||
"projectId": "7ffbb072-2575-495a-b5b0-127f88caef78",
|
||
"credentials": {
|
||
"accessKeyId": "...",
|
||
"secretKey": "..."
|
||
}
|
||
}'
|
||
```
|
||
|
||
### Sample response
|
||
|
||
```bash Response
|
||
{
|
||
"appConnection": {
|
||
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||
"name": "my-aws-connection",
|
||
"projectId": "7ffbb072-2575-495a-b5b0-127f88caef78",
|
||
"version": 123,
|
||
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||
"createdAt": "2023-11-07T05:31:56Z",
|
||
"updatedAt": "2023-11-07T05:31:56Z",
|
||
"app": "aws",
|
||
"method": "access-key",
|
||
"credentials": {
|
||
"accessKeyId": "..."
|
||
}
|
||
}
|
||
}
|
||
```
|
||
</Tab>
|
||
</Tabs>
|
||
</Step>
|
||
</Steps>
|
||
|
||
</Tab>
|
||
|
||
</Tabs>
|