6 ms·
How to manage any kind of secret with AWS Secrets Manager
- scarface74 8y agoAWS’s secret manager seems like overkill for most projects and it’s expensive - 40 cents per secret per month. The Parameter Store is free and much better integrated with AWS’s other offerings. It also supports encrypted values.
- some_account 8y agoOuch, that is very expensive indeed. Normally AWS has decent prices but this seems way too much per secret.
- judge2020 8y agoI imagine parameter store keeps values non-encrypted while secret manager values end up encrypted by a HSM, without the cost of cloudHSM.
- scarface74 8y agoOne of the options when you are adding a parameter is “securestring”. It uses AWS KMS to encrypt your parameter. https://docs.aws.amazon.com/kms/latest/developerguide/services-parameter-store.html https://docs.aws.amazon.com/kms/latest/developerguide/servic...
- dastbe 8y ago(I do work for AWS) I was confused by the naming convention at launch, but a secret is a set of key value pairs and not a single key value pair.
- scarface74 8y agoI’m looking at the Boto3 docs. It looks like a “secret” is a single key where the value can be JSON text that is a key value pair. Parameter Store let’s you use do a simple key value pair. Am I missing something?
- tbrock 8y agoWho says the value needs to represent a scalar value? Why not encode an encrypted JSON string as the value.
- scarface74 8y agoIt kind of defeats the purpose if you are sharing common setting across services, if you only need one value shared.
- empath75 8y agoHave you looked at what hashicorp charges for vault? It's like $150k per cluster.
- scarface74 8y agoVault is free and open source. Only the “Enterprise” version cost money. I’ve used the open source versions of Consul, Nomad, and Vault before for on prem implementation.
- jasonlotito 8y ago> Only the “Enterprise” version cost money. Which is what we are comparing here. Enterprise with enterprise. Features equivalency.
- scarface74 8y agoWhat does the Enterprise version give you that makes it closer to being equivalent to AWS’s secrets manager?
- empath75 8y agoCustomer support.
- packetized 8y agoI see you’re not familiar with AWS customer support.
- sharms 8y agoNot shilling for AWS, but I file at least 1 ticket a month. I haven't tried the phone option, but the web option works for resolving my complaints within 24 hours. My use case might be different since the entire architecture is HA / ephemeral and I can spin up new instances etc while waiting on them.
- djhworld 8y agoWe use parameter store, the thing that makes me nervous about it is there's no SLA on it. As it's free, what incentive do they have to improve it? Additionally they might just retire it in favour of the secrets manager soon anyway. I bet the pricing on that would drop at that point too
- ranman 8y agoHey. I work for AWS. Parameter Store isn’t going away and is still under active development.
- raverbashing 8y agoSo it looks more like a KMS system than let's say Chef Vault
- eropple 8y agoThis write-up is solid - but man, this product looks questionable. 40 cents per secret per month? With Credstash[0] or a moral equivalent[1] you pay a buck for a KMS key and microcents for the data storage. RDS rotation is...fine, I guess, if you have an auditor who really wants that and can't write a scheduled job for the task (I've been using one with credstash so long it's just an automatic part of a new environment), but it's got me skeptical. Something AWS could do, and I'd be very interested in, is a hosted moral equivalent to Vault. Give me a daemon or something to run on an instance, allow me to IAM-gate temporary SSH credentials (and chuck it in CloudTrail) and temporary SQL databases, and that I'd pay for 'cause I really don't want to deal with Vault or HashiCorp. But AWS Secrets Manager, by itself, doesn't really present a good reason-for-being to me. [0] - https://github.com/fugue/credstash https://github.com/fugue/credstash [1] - https://github.com/codahale/sneaker https://github.com/codahale/sneaker
- Spooky23 8y agoIt’s replacing enterprise products that cost way more to meet compliance requirements. It would have saved me about $50k on a project awhile back. No open source product will meet the requirement, because you often need FIPS validated crypto.
- viraptor 8y ago> No open source product will meet the requirement, because you often need FIPS validated crypto. What do you mean? Redhat has FIPS mode. Openssl has FIPS object module. You can create a secrets storage product out of those blocks. Do you mean some specific requirements for the project you were working on?
- Spooky23 8y agoRolling your own is expensive if you’re getting audited for compliance that includes FIPS or other things. You need to have a Dev who understands and documents everything, your ops guys need to be careful to not fix a security bug in OpenSSL that leaves you with a non-validated version, etc. Or you can give AWS $5/secret/year. It’s the path of least resistance.