4 ms·
I have a lambda that runs every day to cycle the RDS master password. I create the password using the random provider, and save it to a secrets manager secret -
by gtsteve 6y ago
I have a lambda that runs every day to cycle the RDS master password. I create the password using the random provider, and save it to a secrets manager secret - the first time the environment is created, the secret is in plaintext in the state, but it will not be valid the next time the lambda runs (less than 24 hours).
You can do the same with ElastiCache auth tokens, and ensure your application reads the token from a value in secrets manager.
- ec109685 6y agoIs there a race condition with the way you rotate the passwords?
- gtsteve 6y agoNo, once you've logged in with MySQL, changing the password doesn't close the connection. For rotating application passwords we use the same technique but we update the usernames, i.e. app_1@'%' becomes app_2@'%', and then rotates back to app_1@'%' to prevent issues with unsynced config files.
- deleted 6y ago[deleted]