AWS teams struggle to manage SecureString values in IaC
In the reported workflows, infrastructure developers have trouble creating and referencing SSM SecureString parameters through CloudFormation and CDK. They resort to manual setup, custom resources, or Secrets Manager; one user says the latter can become costly at scale. A related CLI request highlights another friction point: passing secrets as command-line arguments can expose them in process tables.
For AWS infrastructure developers. Mentioned from Aug 2019 to Apr 2023 on GitHub.
4 different people described this problem in 3 separate discussions.
- Indie fit
- 3.0/10
- Pain
- 6.5/10
- Frequency
- 5.8/10
- Willingness to pay
- 0.0/10
- Momentum
- 5.0/10
- Who pays
- Professionals
- Competition
- Medium
- Build difficulty
- Medium
What people said
Quoted word for word. Follow a link to read the whole discussion.
We currently get around this using 3 ways: 1. Manual SecureString Parameter creation pre stack create. 2. Addition lambda function to create the secure parameter (Add complexity to the template). 3. Create and use Secrets Manager. (This works well however at scale the cost of Secrets Manager become prohibitive)
benlucas11 on GitHub (aws-cloudformation/cloudformation-coverage-roadmap)Aug 2019+202 upvotesAsked for a toolHas a workaroundIf you're ok with using a custom resource, then this is a great solution - https://github.com/glassechidna/ssmcfn, I'm using it for creating SecureString parameters with a dummy initial value "empty
Build brief
See what to build and who will buy it
- 2 product ideas with the smallest useful version and pricing
- 4 places to find your first customers
- 2 more quotes from people who have this problem
- Current workarounds, existing solutions and risks