Description
Writing BasicAuthConfig.Password directly in a CloudFormation AWS::Amplify::Branch, or in a parameter Default, leaves the branch’s password in the template and history.
Potential impact
An exposed username and password can allow unauthorized access to the protected branch site. Other branches that reuse the password may also be affected.
Remediation
Reference the password from Secrets Manager and keep it out of parameter defaults. Replace an exposed password and update the Amplify branch resource to apply the new value. Changing the secret alone does not refresh the branch configuration.
Examples
Supply an existing app ID as AmplifyAppId and the target branch name as BranchName. The original password is illustrative. The revised template generates and references a separate Basic Auth password.
Before
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
AmplifyAppId:
Type: String
BranchName:
Type: String
Resources:
NewAmpApp1:
Type: AWS::Amplify::Branch
Properties:
AppId: !Ref AmplifyAppId
BranchName: !Ref BranchName
EnableAutoBuild: false
EnablePerformanceMode: false
EnablePullRequestPreview: false
BasicAuthConfig:
EnableBasicAuth: true
Password: "@skdsjdk0234!AB"
Username: admin
After
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
AmplifyAppId:
Type: String
BranchName:
Type: String
Resources:
NewAmpApp1:
Type: AWS::Amplify::Branch
Properties:
AppId: !Ref AmplifyAppId
BranchName: !Ref BranchName
EnableAutoBuild: false
EnablePerformanceMode: false
EnablePullRequestPreview: false
BasicAuthConfig:
EnableBasicAuth: true
Password: !Sub '{{resolve:secretsmanager:${MyAmpAppSecretManagerRotater}:SecretString:password}}'
Username: !Sub '{{resolve:secretsmanager:${MyAmpAppSecretManagerRotater}:SecretString:username}}'
MyAmpAppSecretManagerRotater:
Type: AWS::SecretsManager::Secret
Properties:
GenerateSecretString:
SecretStringTemplate: '{"username": "admin"}'
GenerateStringKey: password
PasswordLength: 16