Plaintext master password in a DocumentDB cluster

Keep DocumentDB master passwords out of templates and parameter defaults.

Description

Writing MasterUserPassword directly in CloudFormation’s AWS::DocDB::DBCluster, or in a parameter Default, leaves the master account password in the template and repository history.

Potential impact

Someone who can connect to the cluster and obtain the password could read, change, or delete data with the master account’s privileges.

Remediation

Supply the password securely without a default, or use DocumentDB password management with Secrets Manager. Set NoEcho: true on a password parameter and keep its value out of outputs and logs. Replace an exposed password on the cluster and update application connection credentials.

Examples

These examples compare credential delivery for a new cluster. Supply an existing subnet group and a supported engine version; configure DB instances and access controls separately. The revised password must contain 8–100 printable ASCII characters, excluding /, ", and @. The original password is illustrative.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  DBSubnetGroupName:
    Type: String
  EngineVersion:
    Type: String
Resources:
  NewAmpApp:
    Type: AWS::DocDB::DBCluster
    Properties:
      BackupRetentionPeriod: 8
      DBClusterIdentifier: sample-cluster
      DBSubnetGroupName: !Ref DBSubnetGroupName
      EngineVersion: !Ref EngineVersion
      DeletionProtection: true
      MasterUsername: docdbadmin
      MasterUserPassword: "asDjskjs73!!"
      Port: 27017
      PreferredBackupWindow: 07:34-08:04
      PreferredMaintenanceWindow: sat:04:51-sat:05:21
      StorageEncrypted: true

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  ParentMasterPassword:
    Type: String
    NoEcho: true
    MinLength: 8
    MaxLength: 100
  DBSubnetGroupName:
    Type: String
  EngineVersion:
    Type: String
Resources:
  NewAmpApp:
    Type: AWS::DocDB::DBCluster
    Properties:
      BackupRetentionPeriod: 8
      DBClusterIdentifier: sample-cluster
      DBSubnetGroupName: !Ref DBSubnetGroupName
      EngineVersion: !Ref EngineVersion
      DeletionProtection: true
      MasterUsername: docdbadmin
      MasterUserPassword: !Ref ParentMasterPassword
      Port: 27017
      PreferredBackupWindow: 07:34-08:04
      PreferredMaintenanceWindow: sat:04:51-sat:05:21
      StorageEncrypted: true

References