Plaintext password in a DMS endpoint

Keep DMS endpoint passwords out of templates and parameter defaults.

Description

Writing Password directly in CloudFormation’s AWS::DMS::Endpoint, or in a parameter Default, leaves the source or target data store’s password in code and history.

Potential impact

An exposed credential and a network path to the database can allow unauthorized data access within the account’s permissions.

Remediation

Supply the password securely from outside the template. For a parameter, omit the default, set NoEcho: true, and keep the value out of logs and outputs. Supported endpoints can also use Secrets Manager integration. If a password is exposed, update both the database account and the DMS connection details, then test connectivity.

Examples

This example defines a PostgreSQL source endpoint. Supply the server, database name, and username for your environment. The revised template takes the existing account’s password securely through ParentMasterPassword. Do not use the illustrative password in a real environment.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  DatabaseServer:
    Type: String
  DatabaseName:
    Type: String
  ParentMasterUsername:
    Type: String
Resources:
  DMSEndpoint1:
    Type: AWS::DMS::Endpoint
    Properties:
      EndpointType: source
      EngineName: postgres
      DatabaseName: !Ref DatabaseName
      Password: "asDjskjs73!!"
      Port: 5432
      ServerName: !Ref DatabaseServer
      Username: !Ref ParentMasterUsername
      SslMode: require

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  ParentMasterPassword:
    Type: String
    NoEcho: true
  DatabaseServer:
    Type: String
  DatabaseName:
    Type: String
  ParentMasterUsername:
    Type: String
Resources:
  DMSEndpoint1:
    Type: AWS::DMS::Endpoint
    Properties:
      EndpointType: source
      EngineName: postgres
      DatabaseName: !Ref DatabaseName
      Password: !Ref ParentMasterPassword
      Port: 5432
      ServerName: !Ref DatabaseServer
      Username: !Ref ParentMasterUsername
      SslMode: require

References