Description
Writing Password directly in CloudFormation’s AWS::DMS::Endpoint, or in a parameter Default, leaves the source or target data store’s password in code and history.
Potential impact
An exposed credential and a network path to the database can allow unauthorized data access within the account’s permissions.
Remediation
Supply the password securely from outside the template. For a parameter, omit the default, set NoEcho: true, and keep the value out of logs and outputs. Supported endpoints can also use Secrets Manager integration. If a password is exposed, update both the database account and the DMS connection details, then test connectivity.
Examples
This example defines a PostgreSQL source endpoint. Supply the server, database name, and username for your environment. The revised template takes the existing account’s password securely through ParentMasterPassword. Do not use the illustrative password in a real environment.
Before
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
DatabaseServer:
Type: String
DatabaseName:
Type: String
ParentMasterUsername:
Type: String
Resources:
DMSEndpoint1:
Type: AWS::DMS::Endpoint
Properties:
EndpointType: source
EngineName: postgres
DatabaseName: !Ref DatabaseName
Password: "asDjskjs73!!"
Port: 5432
ServerName: !Ref DatabaseServer
Username: !Ref ParentMasterUsername
SslMode: require
After
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
ParentMasterPassword:
Type: String
NoEcho: true
DatabaseServer:
Type: String
DatabaseName:
Type: String
ParentMasterUsername:
Type: String
Resources:
DMSEndpoint1:
Type: AWS::DMS::Endpoint
Properties:
EndpointType: source
EngineName: postgres
DatabaseName: !Ref DatabaseName
Password: !Ref ParentMasterPassword
Port: 5432
ServerName: !Ref DatabaseServer
Username: !Ref ParentMasterUsername
SslMode: require