Secrets Manager KMS key not specified

Check secret key-management and cross-account access requirements.

Description

If KmsKeyId is omitted, Secrets Manager encrypts the secret with the AWS managed aws/secretsmanager key. Policies requiring customer managed keys, and cross-account access, require selecting a separate key.

Potential impact

The default key cannot meet a requirement to manage the key policy directly and cannot be used for cross-account access.

Remediation

Specify the required customer managed key in KmsKeyId. Cross-account access also needs the secret’s resource policy, IAM permissions, and KMS key policy; selecting a key alone does not grant access.

Examples

These excerpts show the property structure, with String standing in for actual inputs. Do not hardcode real secret values in templates.

Before

yaml
Resources:
  SecretsManagerSecret:
    Type: AWS::SecretsManager::Secret
    Properties:
      Description: String
      Name: String
      SecretString: String

After

yaml
Resources:
  SecretsManagerSecret:
    Type: AWS::SecretsManager::Secret
    Properties:
      Description: String
      KmsKeyId: String
      Name: String
      SecretString: String

References