Amazon AWS Secrets Manager
The Amazon AWS Secrets Manager connector enables secure storage, retrieval, and management of sensitive information like passwords and API keys.
AWS Secrets Manager is a secure vault service that centralizes the storage and management of sensitive information such as passwords, tokens, and API keys. This connector enables Swimlane Turbine users to automate the lifecycle of secrets, including creation, retrieval, and rotation, directly within their security workflows. By integrating with AWS Secrets Manager, Swimlane Turbine enhances security posture by ensuring that secrets are encrypted, access-controlled, and auditable, while reducing the risk of secret sprawl and hard-coded credentials in code.
Asset Setup
This integration authenticates with AWS Secrets Manager using the following input values:
Prerequisites
To utilize the Amazon AWS Secrets Manager connector within Swimlane Turbine, ensure you have the following:
- AWS Secrets Manager authentication credentials:
- Access Key: Your AWS IAM user's access key ID.
- Secret Key: Your AWS IAM user's secret access key.
- Region Name: The AWS region where your secrets are stored.
Obtaining AWS Credentials
To use this integration, you will need to have an AWS account and obtain the necessary AWS credentials. You can obtain these credentials by following the steps below:
- Log in to your AWS account and navigate to the IAM console.
- In the left navigation pane, click on the "Users" tab and select the user for which you want to create credentials.
- Click on the "Security credentials" tab, and then click on "Create access key".
- Make sure to save the access key ID and secret access key in a secure location, as you will not be able to see the secret access key again after this step.
- If you want to use an AWS IAM Role to access the Secrets Manager, you will need to have the ARN of the role and an optional External ID, if one was specified by the AWS account administrator.
Permissions
- Open the IAM Management Console.
- Navigate to the user or role that requires the permission.
- Click on the permissions tab and then click on the add permissions button at the right side top corner of the permissions block.
- Click on Attach Policies and search for SecretsManagerReadWrite permissions policies.
- Select the box of SecretsManagerReadWrite and then click on the Add Permissions button at the right side bottom corner.
Capabilities
The AWS Secrets Manager Connector provides the following capabilities:
- Create Secret
- Delete Secret
- Get Secret Value
- List Secrets
- Put Secret Value
- Tag Resource
Notes
Configurations
AWS Secrets Manager Auth
Authenticates using AWS credentials
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
access_key | AWS Access Key. | string | Required |
secret_key | AWS Secret Key . | string | Required |
region_name | The AWS Region where you want to create new connections | string | Required |
role_arn | Optional Role ARN to assume. Leave blank unless tasks need to assume a different role. | string | Optional |
external_id | External ID to assume IAM Role. Optional value used for assuming roles. Can be added, or removed in Trusted Relationships of target role. | string | Optional |
session_token | Use if a session token is provided when switching roles | string | Optional |
role_session_name | Defaults to SessionFromSwimlane_<HASH> when no value is provide | string | Optional |
Actions
Create Secret
Creates a new encrypted secret in Amazon AWS Secrets Manager for secure storage and management of passwords or credentials.
Endpoint
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
Name | string | Required | The name of the new secret. The secret name can contain ASCII letters, numbers, and the following characters are /_+=.@-. |
ClientRequestToken | string | Optional | If you include SecretString or SecretBinary, then Secrets Manager creates an initial version for the secret, and this parameter specifies the unique identifier for the new version. |
Description | string | Optional | The description of the secret. |
KmsKeyId | string | Optional | The ARN, key ID, or alias of the KMS key that Secrets Manager uses to encrypt the secret value in the secret. |
SecretBinary | string | Optional | The binary data to encrypt and store in the new version of the secret. |
SecretString | string | Optional | The text data to encrypt and store in this new version of the secret. |
Tags | array | Optional | A list of tags to attach to the secret. |
Tags.Key | string | Optional | The key identifier, or name, of the tag. |
Tags.Value | string | Optional | The string value associated with the key of the tag. |
AddReplicaRegions | array | Optional | A list of Regions and KMS keys to replicate secrets. |
AddReplicaRegions.Region | string | Optional | A Region code. |
AddReplicaRegions.KmsKeyId | string | Optional | The ARN, key ID, or alias of the KMS key to encrypt the secret. |
ForceOverwriteReplicaSecret | boolean | Optional | Specifies whether to overwrite a secret with the same name in the destination Region. |
Input Example
{"Name":"MyTestDatabaseSecret","ClientRequestToken":"EXAMPLE1-90ab-cdef-fedc-ba987SECRET1","Description":"My test database secret created with the CLI","KmsKeyId":"test12312321","SecretBinary":"Secret Binary","SecretString":"{'username':'david','password':'EXAMPLE-PASSWORD'}","Tags":[{"Key":"CostCenter","Value":"12345"},{"Key":"environment","Value":"production"}],"AddReplicaRegions":[{"Region":"us-east-1","KmsKeyId":"test123123214"}],"ForceOverwriteReplicaSecret":true}
Output
Parameter | Type | Description |
|---|---|---|
ARN | string | Output field: ARN |
Name | string | Name of the resource |
VersionId | string | Unique identifier |
ResponseMetadata | object | Response data |
ResponseMetadata.RequestId | string | Response data |
ResponseMetadata.HTTPStatusCode | number | Response data |
ResponseMetadata.HTTPHeaders | object | Response data |
ResponseMetadata.HTTPHeaders.x-amzn-requestid | string | Response data |
ResponseMetadata.HTTPHeaders.content-type | string | Response data |
ResponseMetadata.HTTPHeaders.content-length | string | Response data |
ResponseMetadata.HTTPHeaders.date | string | Response data |
ResponseMetadata.RetryAttempts | number | Response data |
Output Example
{"ARN":"arn:aws:secretsmanager:ap-south-1:471112629208:secret:MyTestDatabaseSecret-PHECb...","Name":"MyTestDatabaseSecret","VersionId":"EXAMPLE1-90ab-cdef-fedc-ba987SECRET1","ResponseMetadata":{"RequestId":"8ae3bea3-0a90-46a7-9883-1b2a0ef23413","HTTPStatusCode":200,"HTTPHeaders":{"x-amzn-requestid":"8ae3bea3-0a90-46a7-9883-1b2a0ef23413","content-type":"application/x-amz-json-1.1","content-length":"172","date":"Fri, 26 Jul 2024 \n 15:51:17 GMT"},"RetryAttempts":0}}
Delete Secret
Permanently removes a specified secret and its versions from Amazon AWS Secrets Manager, with an optional recovery period.
Endpoint
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
SecretId | string | Required | The ARN or name of the secret to delete. |
RecoveryWindowInDays | number | Optional | The number of days from 7 to 30 that Secrets Manager waits before permanently deleting the secret. You can't use both this parameter and ForceDeleteWithoutRecovery in the same call. |
ForceDeleteWithoutRecovery | boolean | Optional | Specifies whether to delete the secret without any recovery window. |
Input Example
{"SecretId":"MyTestDatabaseSecret","RecoveryWindowInDays":7,"ForceDeleteWithoutRecovery":true}
Output
Parameter | Type | Description |
|---|---|---|
ARN | string | Output field: ARN |
Name | string | Name of the resource |
DeletionDate | string | Date value |
ResponseMetadata | object | Response data |
ResponseMetadata.RequestId | string | Response data |
ResponseMetadata.HTTPStatusCode | number | Response data |
ResponseMetadata.HTTPHeaders | object | Response data |
ResponseMetadata.HTTPHeaders.x-amzn-requestid | string | Response data |
ResponseMetadata.HTTPHeaders.content-type | string | Response data |
ResponseMetadata.HTTPHeaders.content-length | string | Response data |
ResponseMetadata.HTTPHeaders.date | string | Response data |
ResponseMetadata.RetryAttempts | number | Response data |
Output Example
{"ARN":"arn:aws:secretsmanager:ap-south-1:471112629208:secret:MyTestDatabaseSecret-PHECb...","Name":"MyTestDatabaseSecret","DeletionDate":"2024-08-28 05:50:04","ResponseMetadata":{"RequestId":"bd225cc4-7333-4934-ba87-17f800c06e7a","HTTPStatusCode":200,"HTTPHeaders":{"x-amzn-requestid":"bd225cc4-7333-4934-ba87-17f800c06e7a","content-type":"application/x-amz-json-1.1","content-length":"153","date":"Mon, 29 Jul 2024 05:50:04 GMT"},"RetryAttempts":0}}
Get Secret Value
Retrieves the encrypted content of a specified secret from Amazon AWS Secrets Manager using its unique identifier.
Endpoint
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
SecretId | string | Required | The ARN or name of the secret to retrieve. To retrieve a secret from another account, you must use an ARN. |
VersionId | string | Optional | The unique identifier of the version of the secret to retrieve. If you include both this parameter and VersionStage, the two parameters must refer to the same secret version. If you don't specify either a VersionStage or VersionId, then Secrets Manager returns the AWSCURRENT version. This value is typically a UUID-type value with 32 hexadecimal digits. |
VersionStage | string | Optional | The staging label of the version of the secret to retrieve. |
Input Example
{"SecretId":"MyTestDatabaseSecret","VersionId":"6138ae16-59cf-4b73-8eba-987a36b67903","VersionStage":"AWSCURRENT"}
Output
Parameter | Type | Description |
|---|---|---|
ARN | string | Output field: ARN |
Name | string | Name of the resource |
VersionId | string | Unique identifier |
SecretString | string | Output field: SecretString |
VersionStages | array | Output field: VersionStages |
CreatedDate | string | Date value |
ResponseMetadata | object | Response data |
ResponseMetadata.RequestId | string | Response data |
ResponseMetadata.HTTPStatusCode | number | Response data |
ResponseMetadata.HTTPHeaders | object | Response data |
ResponseMetadata.HTTPHeaders.x-amzn-requestid | string | Response data |
ResponseMetadata.HTTPHeaders.content-type | string | Response data |
ResponseMetadata.HTTPHeaders.content-length | string | Response data |
ResponseMetadata.HTTPHeaders.date | string | Response data |
ResponseMetadata.RetryAttempts | number | Response data |
Output Example
{"ARN":"arn:aws:secretsmanager:ap-south-1:471112629208:secret:MyTestDatabaseSecret-PHECb...","Name":"MyTestDatabaseSecret","VersionId":"6138ae16-59cf-4b73-8eba-987a36b67903","SecretString":"{'username':'david','password':'EXAMPLE-PASSWORD1'}","VersionStages":["AWSCURRENT"],"CreatedDate":"2024-07-26 16:09:21","ResponseMetadata":{"RequestId":"7a2f8185-101e-4912-9f9a-9c5f760d0a67","HTTPStatusCode":200,"HTTPHeaders":{"x-amzn-requestid":"7a2f8185-101e-4912-9f9a-9c5f760d0a67","content-type":"applicati...
List Secrets
Retrieve a list of all secrets from Amazon AWS Secrets Manager, excluding any marked for deletion.
Endpoint
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
IncludePlannedDeletion | boolean | Optional | Specifies whether to include secrets scheduled for deletion. |
MaxResults | number | Optional | The number of results to include in the response. |
NextToken | string | Optional | A token that indicates where the output should continue from, if a previous call did not show all results. |
Filters | array | Optional | The filters to apply to the list of secrets. |
Filters.Key | string | Optional | Key used to filter. |
Filters.Values | array | Optional | The keyword to filter for. You can prefix your search value with an exclamation mark ( !) in order to perform negation filters. |
SortOrder | string | Optional | Secrets are listed by CreatedDate. |
Input Example
{"IncludePlannedDeletion":false,"MaxResults":10,"NextToken":"ewrwe2435213edf12345","Filters":[{"Key":"name","Values":["MyTestDatabaseSecret"]}],"SortOrder":"asc"}
Output
Parameter | Type | Description |
|---|---|---|
SecretList | array | Output field: SecretList |
SecretList.ARN | string | Output field: SecretList.ARN |
SecretList.Name | string | Name of the resource |
SecretList.Description | string | Output field: SecretList.Description |
SecretList.LastChangedDate | string | Date value |
SecretList.LastAccessedDate | string | Date value |
SecretList.Tags | array | Output field: SecretList.Tags |
SecretList.Tags.Key | string | Output field: SecretList.Tags.Key |
SecretList.Tags.Value | string | Value for the parameter |
SecretList.SecretVersionsToStages | object | Output field: SecretList.SecretVersionsToStages |
SecretList.SecretVersionsToStages.6138ae16-59cf-4b73-8eba-987a36b67903 | array | Output field: SecretList.SecretVersionsToStages.6138ae16-59cf-4b73-8eba-987a36b67903 |
SecretList.SecretVersionsToStages.EXAMPLE1-90ab-cdef-fedc-ba987SECRET1 | array | Output field: SecretList.SecretVersionsToStages.EXAMPLE1-90ab-cdef-fedc-ba987SECRET1 |
SecretList.CreatedDate | string | Date value |
ResponseMetadata | object | Response data |
ResponseMetadata.RequestId | string | Response data |
ResponseMetadata.HTTPStatusCode | number | Response data |
ResponseMetadata.HTTPHeaders | object | Response data |
ResponseMetadata.HTTPHeaders.x-amzn-requestid | string | Response data |
ResponseMetadata.HTTPHeaders.content-type | string | Response data |
ResponseMetadata.HTTPHeaders.content-length | string | Response data |
ResponseMetadata.HTTPHeaders.date | string | Response data |
ResponseMetadata.RetryAttempts | number | Response data |
Output Example
{"SecretList":[{"ARN":"arn:aws:secretsmanager:ap-south-1:471112629208:secret:MyTestDatabaseSecret-PHECb...","Name":"MyTestDatabaseSecret","Description":"My test database secret created with the CLI","LastChangedDate":"2024-07-26 17:28:26","LastAccessedDate":"2024-07-28 00:00:00","Tags":[],"SecretVersionsToStages":{},"CreatedDate":"2024-07-26 15:51:17"}],"ResponseMetadata":{"RequestId":"b996b0ea-c96d-4917-881e-4ff3edb86f46","HTTPStatusCode":200,"HTTPHeaders":{"x-amzn-requestid":"b996b0ea-c96d-491...
Put Secret Value
Creates a new encrypted version of the secret value in Amazon AWS Secrets Manager using the provided SecretId.
Endpoint
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
SecretId | string | Required | The ARN or name of the secret to add a new version to. |
ClientRequestToken | string | Optional | A unique identifier for the new version of the secret. |
SecretBinary | string | Optional | The binary data to encrypt and store in the new version of the secret. |
SecretString | string | Optional | The text to encrypt and store in the new version of the secret. |
VersionStages | array | Optional | A list of staging labels to attach to this version of the secret. Secrets Manager uses staging labels to track versions of a secret through the rotation process. |
RotationToken | string | Optional | A unique identifier that indicates the source of the request. |
Input Example
{"SecretId":"MyTestDatabaseSecret","ClientRequestToken":"6138ae16-59cf-4b73-8eba-987a36b67913","SecretBinary":"Secret Binary Value","SecretString":"{'username':'david','password':'EXAMPLE-PASSWORD1'}","VersionStages":["AWSCURRENT"],"RotationToken":"afgvwegsdv2345342efd"}
Output
Parameter | Type | Description |
|---|---|---|
ARN | string | Output field: ARN |
Name | string | Name of the resource |
VersionId | string | Unique identifier |
VersionStages | array | Output field: VersionStages |
ResponseMetadata | object | Response data |
ResponseMetadata.RequestId | string | Response data |
ResponseMetadata.HTTPStatusCode | number | Response data |
ResponseMetadata.HTTPHeaders | object | Response data |
ResponseMetadata.HTTPHeaders.x-amzn-requestid | string | Response data |
ResponseMetadata.HTTPHeaders.content-type | string | Response data |
ResponseMetadata.HTTPHeaders.content-length | string | Response data |
ResponseMetadata.HTTPHeaders.date | string | Response data |
ResponseMetadata.RetryAttempts | number | Response data |
Output Example
{"ARN":"arn:aws:secretsmanager:ap-south-1:471112629208:secret:MyTestDatabaseSecret-PHECb...","Name":"MyTestDatabaseSecret","VersionId":"6138ae16-59cf-4b73-8eba-987a36b67903","VersionStages":["AWSCURRENT"],"ResponseMetadata":{"RequestId":"fb223972-194a-4753-aad3-e30ac1ca4bd9","HTTPStatusCode":200,"HTTPHeaders":{"x-amzn-requestid":"fb223972-194a-4753-aad3-e30ac1ca4bd9","content-type":"application/x-amz-json-1.1","content-length":"203","date":"Fri, 26 Jul 2024 16:09:21 GMT"},"RetryAttempts":0}}
Tag Resource
Attaches key-value tags to a specified secret in Amazon AWS Secrets Manager, enhancing its metadata.
Endpoint
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
SecretId | string | Required | The identifier for the secret to attach tags to. You can specify either the Amazon Resource Name (ARN) or the friendly name of the secret. |
Tags | array | Required | The tags to attach to the secret as a JSON text string argument. Each element in the list consists of a Key and a Value. |
Tags.Key | string | Required | The key identifier, or name, of the tag. |
Tags.Value | string | Required | The string value associated with the key of the tag. |
Input Example
{"SecretId":"MyTestDatabaseSecret","Tags":[{"Key":"FirstTag","Value":"SomeValue"},{"Key":"SecondTag","Value":"AnotherValue"}]}
Output
Parameter | Type | Description |
|---|---|---|
ResponseMetadata | object | Response data |
ResponseMetadata.RequestId | string | Response data |
ResponseMetadata.HTTPStatusCode | number | Response data |
ResponseMetadata.HTTPHeaders | object | Response data |
ResponseMetadata.HTTPHeaders.x-amzn-requestid | string | Response data |
ResponseMetadata.HTTPHeaders.content-type | string | Response data |
ResponseMetadata.HTTPHeaders.content-length | string | Response data |
ResponseMetadata.HTTPHeaders.date | string | Response data |
ResponseMetadata.RetryAttempts | number | Response data |
Output Example
{"ResponseMetadata":{"RequestId":"1667fe69-b8ac-4aa2-b698-2a8425d74aa5","HTTPStatusCode":200,"HTTPHeaders":{"x-amzn-requestid":"1667fe69-b8ac-4aa2-b698-2a8425d74aa5","content-type":"application/x-amz-json-1.1","content-length":"0","date":"Fri, 26 Jul 2024 17:28:26 GMT"},"RetryAttempts":0}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |