Exposed Amplify app access token

Putting an Amplify app access token in a template leaves credentials in deployment code and history.

Description

The AccessToken property of CloudFormation’s AWS::Amplify::App is a personal access token that authorizes a GitHub repository connection. A literal value or a parameter Default leaves the credential in the template and repository history.

Potential impact

Someone who can read the template may obtain the token and access GitHub resources within its permissions.

Remediation

Store a token issued by GitHub in Secrets Manager and pass it through a dynamic reference. Keep tokens out of parameter defaults. Revoke an exposed token in GitHub and replace it with a new one.

Examples

Supply the GitHub repository URL as RepositoryUrl. The revised template also takes the name or ARN of an existing Secrets Manager secret containing the real token under the token key. The token below is illustrative; a randomly generated password cannot replace a GitHub token.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  RepositoryUrl:
    Type: String
Resources:
  NewAmpApp:
    Type: AWS::Amplify::App
    Properties:
      Name: NewAmpApp
      Repository: !Ref RepositoryUrl
      AccessToken: ghp_EXAMPLE_NOT_A_REAL_GITHUB_TOKEN

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  RepositoryUrl:
    Type: String
  MyAmpAppSecretManagerRotater:
    Type: String
Resources:
  NewAmpApp:
    Type: AWS::Amplify::App
    Properties:
      Name: NewAmpApp
      Repository: !Ref RepositoryUrl
      AccessToken: !Sub '{{resolve:secretsmanager:${MyAmpAppSecretManagerRotater}:SecretString:token}}'

References