Description
The AccessToken property of CloudFormation’s AWS::Amplify::App is a personal access token that authorizes a GitHub repository connection. A literal value or a parameter Default leaves the credential in the template and repository history.
Potential impact
Someone who can read the template may obtain the token and access GitHub resources within its permissions.
Remediation
Store a token issued by GitHub in Secrets Manager and pass it through a dynamic reference. Keep tokens out of parameter defaults. Revoke an exposed token in GitHub and replace it with a new one.
Examples
Supply the GitHub repository URL as RepositoryUrl. The revised template also takes the name or ARN of an existing Secrets Manager secret containing the real token under the token key. The token below is illustrative; a randomly generated password cannot replace a GitHub token.
Before
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
RepositoryUrl:
Type: String
Resources:
NewAmpApp:
Type: AWS::Amplify::App
Properties:
Name: NewAmpApp
Repository: !Ref RepositoryUrl
AccessToken: ghp_EXAMPLE_NOT_A_REAL_GITHUB_TOKEN
After
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
RepositoryUrl:
Type: String
MyAmpAppSecretManagerRotater:
Type: String
Resources:
NewAmpApp:
Type: AWS::Amplify::App
Properties:
Name: NewAmpApp
Repository: !Ref RepositoryUrl
AccessToken: !Sub '{{resolve:secretsmanager:${MyAmpAppSecretManagerRotater}:SecretString:token}}'