Description
If KmsKeyId is omitted, Secrets Manager encrypts the secret with the AWS managed aws/secretsmanager key. Policies requiring customer managed keys, and cross-account access, require selecting a separate key.
Potential impact
The default key cannot meet a requirement to manage the key policy directly and cannot be used for cross-account access.
Remediation
Specify the required customer managed key in KmsKeyId. Cross-account access also needs the secret’s resource policy, IAM permissions, and KMS key policy; selecting a key alone does not grant access.
Examples
These excerpts show the property structure, with String standing in for actual inputs. Do not hardcode real secret values in templates.
Before
yaml
Resources:
SecretsManagerSecret:
Type: AWS::SecretsManager::Secret
Properties:
Description: String
Name: String
SecretString: String
After
yaml
Resources:
SecretsManagerSecret:
Type: AWS::SecretsManager::Secret
Properties:
Description: String
KmsKeyId: String
Name: String
SecretString: String